Red Hat Bugzilla – Bug 1016263
CVE-2013-4461 cumin: filtering table operator not checked, leads to potential SQLi
Last modified: 2013-12-17 20:09:28 EST
A flaw was found in the way cumin parsed POST request data. A remote attacker could potentially use this flaw to perform SQL injection attacks on cumin's database.
Acknowledgements: This issue was discovered by Tomáš Nováčik of the Red Hat MRG Quality Engineering team.
This issue has been addressed in following products: MRG for RHEL-6 v.2 Via RHSA-2013:1852 https://rhn.redhat.com/errata/RHSA-2013-1852.html
This issue has been addressed in following products: MRG for RHEL-5 v. 2 Via RHSA-2013:1851 https://rhn.redhat.com/errata/RHSA-2013-1851.html