CVE-2014-2081
20.10.2014, 15:55
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
Vendor | Product | Version |
---|---|---|
iii | vtls-virtua | 2013.2.3 |
iii | vtls-virtua | 2014.1.0 |
𝑥
= Vulnerable software versions