CVE-2014-1645

Symantec LUA <2.3.2.110 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Scores

EPSS 0.0049
EPSS Percentile 65.9%

Details

CWE
CWE-89
Status published
Products (9)
symantec/liveupdate_administrator 2.1.0
symantec/liveupdate_administrator 2.1.2
symantec/liveupdate_administrator 2.1.3
symantec/liveupdate_administrator 2.2.1
symantec/liveupdate_administrator 2.2.2
symantec/liveupdate_administrator 2.2.2.9
symantec/liveupdate_administrator 2.3.0
symantec/liveupdate_administrator 2.3.1
symantec/liveupdate_administrator < 2.3.2
Published Mar 29, 2014
Tracked Since Feb 18, 2026