7.5
CVSSv2

CVE-2013-5694

Published: 05/11/2013 Updated: 07/11/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in status/service/acknowledge in Opsview prior to 4.4.1 allows remote malicious users to execute arbitrary SQL commands via the service_selection parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

opsview opsview 4.2

opsview opsview 4.1

opsview opsview 2.10

opsview opsview 2.8

opsview opsview 2.7

opsview opsview 3.10

opsview opsview 3.8

opsview opsview 3.6

opsview opsview 3.4

opsview opsview 3.2

opsview opsview

opsview opsview 4.3

opsview opsview 4.0

opsview opsview 3.14

opsview opsview 3.1

opsview opsview 2.14

opsview opsview 3.12

opsview opsview 3.0

opsview opsview 2.12

Exploits

CVE-2013-5694 Blind SQL Injection in Ops View Version(s): Opsview pre 441 Author: J Oquendo (joquendo at e-fensive dot net) I ADVISORY Title: Blind SQL Injection in OpsView Date published: 2013-10-28 Vendor contacted: 2013-09-04 II BACKGROUND Opsview is a systems management software built on open source software To minimize noise, read ...
Ops View version pre 4441 suffers from a remote blind SQL injection vulnerability ...