CVE-2013-7369

CWE-89SQL Injection4 documents4 sources
Severity
7.5HIGH
EPSS
0.4%
top 41.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18
Latest updateMay 17

Description

SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Anti-Virus for Windows Servers 9.00 before HF09, Anti-Virus for Citrix Servers 9.00 before HF09, and F-Secure Email and Server Security and F-Secure Server Security 9.20 before HF01 allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to GetCommand.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-cp35-64v5-r4w6: SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Ant2022-05-17
CVEList
CVE-2013-7369: SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Ant2014-04-18

📋Vendor Advisories

1
Citrix
CVE-2013-7369: SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Ant2014-04-18
CVE-2013-7369 (HIGH CVSS 7.5) | SQL injection vulnerability in an u | cvebase.io