« Back to list

CVE-2013-7369

Status: ModifiedHigh (7.5)—

SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Anti-Virus for Windows Servers 9.00 before HF09, Anti-Virus for Citrix Servers 9.00 before HF09, and F-Secure Email and Server Security and F-Secure Server Security 9.20 before HF01 allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to GetCommand.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (3)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2013-7369",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-18T14:55:25.870",
  "references": [
    {
      "url": "http://www.f-secure.com/en/web/labs_global/fsc-2013-1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-13-095/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.f-secure.com/en/web/labs_global/fsc-2013-1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-13-095/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Anti-Virus for Windows Servers 9.00 before HF09, Anti-Virus for Citrix Servers 9.00 before HF09, and F-Secure Email and Server Security and F-Secure Server Security 9.20 before HF01 allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to GetCommand."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de inyección SQL en una DLL no especificada en el control FSDBCom ActiveX en F-Secure Anti-Virus para Microsoft Exchange Server anterior a HF02, Anti-Virus para Windows Servers 9.00 anterior a HF09, Anti-Virus para Citrix Servers 9.00 anterior a HF09, y F-Secure Email y Server Security y F-Secure Server Security 9.20 anterior a HF01 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de vectores desconocidos, relacionado con GetCommand."
    }
  ],
  "lastModified": "2026-06-17T00:01:50.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f-secure:anti-virus:9.00:*:*:*:*:citrix_servers:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A5F5F9D-61C0-4ADE-94C6-5C23B37DC42E"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:anti-virus:9.00:*:*:*:*:exchange_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AD36F65-10CC-431A-94B9-FA3800297383"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:anti-virus:9.00:*:*:*:*:windows_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6F17A1F-616E-48FD-A8C7-7B95F5530CF4"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:anti-virus:9.10:*:*:*:*:exchange_server:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87E8E004-614E-4B8A-A218-00905842AC4E"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:email_and_server_security:9.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B229B4C-BE77-4477-8AE7-A3F03069CC38"
            },
            {
              "criteria": "cpe:2.3:a:f-secure:server_security:9.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12037257-81B4-460F-A0AA-067B365D8EF8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}