CVE-2014-2351

S

QL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:controlsystemworks:csworks:*:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.601.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.612.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.623.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.720.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.801.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.813.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.901.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.3540.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.3560.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.0.3580.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.1.3600.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.1.3674.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.1.3700.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.2.3730.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.2.3800.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.3820.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.3830.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.3850.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.3860.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.3880.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.3900.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.4.4000.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.7.4050.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:1.7.5000.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.0.4115.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.0.4115.1:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.1.4386.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.1.4560.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.5.4770.0:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.5.4770.1:*:*:*:*:*:*:*
cpe:2.3:a:controlsystemworks:csworks:2.5.4912.0:*:*:*:*:*:*:*

History

03 Oct 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-14-135-01 -

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01 - US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01 - US Government Resource
References () http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330 - Vendor Advisory () http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330 - Vendor Advisory
References () http://www.securityfocus.com/bid/67427 - () http://www.securityfocus.com/bid/67427 -

Information

Published : 2014-05-20 11:13

Updated : 2025-10-03 17:15


NVD link : CVE-2014-2351

Mitre link : CVE-2014-2351

CVE.ORG link : CVE-2014-2351


JSON object : View

Products Affected
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')