CVE-2014-5503

CyberoamOS < 10.6.1 - SQL Injection via Guest Login Portal add_guest_user Opcode

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://kb.cyberoam.com/default.asp?id=3049
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-329/

Scores

EPSS 0.0199
EPSS Percentile 78.5%

Details

CWE
CWE-89
Status published
Products (2)
cyberoam/cyberoam_os < 10.4
cyberoam/cyberoam_os < 10.6.1
Published Oct 07, 2014
Tracked Since Feb 18, 2026