Back to Database
Status published
High
CVE-2013-5694
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows...
Vulnerability Description
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-5694
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.com/files/123821/Ops-View-Pre-4.4.1-Blind-SQL-Injection.html
- http://osvdb.org/ref/99/opsview-sqli.txt
- http://docs.opsview.com/doku.php?id=opsview4.4:changes#fixes
- http://www.exploit-db.com/exploits/29326
- http://osvdb.org/99038
- http://www.securityfocus.com/bid/63387
- http://archives.neohapsis.com/archives/bugtraq/2013-10/0149.html
More from opsview
View All →CVE-2018-16148
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor...
Medium
6.1
CVE-2018-16147
The data parameter of the /settings/api/router endpoint in Opsview Monitor...
Medium
6.1
CVE-2018-16146
The web management console of Opsview Monitor 5.4.x before 5.4.2...
High
7.2
CVE-2018-16145
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview...
High
8.1
CVE-2018-16144
The test connection functionality in the NetAudit section of Opsview...
Critical
9.8
Affected Vendor
opsview
View all reports →Affected Software
opsview
Vulnerable Versions:
0, 2.7, 2.8, 2.10, 2.12, 2.14, 3.0, 3.1, 3.2, 3.4, 3.6, 3.8, 3.10, 3.12, 3.14, 4.0, 4.1, 4.2, 4.3
Timeline
Official Publish:
November 5th, 2013
Last Modified:
September 17th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.