SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/97588 - | |
References | () http://www.baesystemsdetica.com.au/Research/Advisories/mod_accounting-Blind-SQL-Injection-%28DS-2013-006%29 - Exploit |
Information
Published : 2013-09-30 21:55
Updated : 2024-11-21 01:57
NVD link : CVE-2013-5697
Mitre link : CVE-2013-5697
CVE.ORG link : CVE-2013-5697
JSON object : View
Products Affected
simone_tellini
- mod_accounting
apache
- http_server
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')