CVE-2014-5503
CyberoamOS < 10.6.1 - SQL Injection via Guest Login Portal add_guest_user Opcode
Title source: llmDescription
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://kb.cyberoam.com/default.asp?id=3049
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-329/
Scores
EPSS
0.0199
EPSS Percentile
78.5%
Details
CWE
CWE-89
Status
published
Products (2)
cyberoam/cyberoam_os
< 10.4
cyberoam/cyberoam_os
< 10.6.1
Published
Oct 07, 2014
Tracked Since
Feb 18, 2026