CVE-2014-1645
29.03.2014, 01:55
SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Vendor | Product | Version |
---|---|---|
symantec | liveupdate_administrator | 𝑥 ≤ 2.3.2 |
symantec | liveupdate_administrator | 2.1.0 |
symantec | liveupdate_administrator | 2.1.2 |
symantec | liveupdate_administrator | 2.1.3 |
symantec | liveupdate_administrator | 2.2.1 |
symantec | liveupdate_administrator | 2.2.2 |
symantec | liveupdate_administrator | 2.2.2.9 |
symantec | liveupdate_administrator | 2.3.0 |
symantec | liveupdate_administrator | 2.3.1 |
𝑥
= Vulnerable software versions
References