CVE-2013-4461
published 2013-12-23CVE-2013-4461: SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.89%
77.2th percentile
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wjw2-3w4f-g496: SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2
ghsa_unreviewed·2022-05-13
CVE-2013-4461 [HIGH] CWE-89 GHSA-wjw2-3w4f-g496: SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
Red Hat
cumin: filtering table operator not checked, leads to potential SQLi
vendor_redhat·2013-12-17·CVSS 7.5
CVE-2013-4461 [HIGH] cumin: filtering table operator not checked, leads to potential SQLi
cumin: filtering table operator not checked, leads to potential SQLi
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
No detection rules found.
No public exploits indexed.
2013-12-23
Published