Leigh Business Enterprises Web HelpDesk SQL Injection Vulnerability
BID:10773
Info
Leigh Business Enterprises Web HelpDesk SQL Injection Vulnerability
| Bugtraq ID: | 10773 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-2562 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Noam Rathaus <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Leigh Business Enterprises Web HelpDesk 4.0 .0.80 |
| Not Vulnerable: |
Leigh Business Enterprises Web HelpDesk 4.0 .0.81 |
Discussion
Leigh Business Enterprises Web HelpDesk SQL Injection Vulnerability
LBE Web HelpDesk is reported susceptible to an SQL injection vulnerability. This issue is due to improper sanitization of user-supplied data.
This issue may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.
Versions 4.0.0.80 and prior are reported vulnerable to this issue.
LBE Web HelpDesk is reported susceptible to an SQL injection vulnerability. This issue is due to improper sanitization of user-supplied data.
This issue may allow a remote attacker to manipulate query logic, potentially leading to unauthorized access to sensitive information or corruption of database data. SQL injection attacks may also potentially be used to exploit latent vulnerabilities in the underlying database implementation.
Versions 4.0.0.80 and prior are reported vulnerable to this issue.
Exploit / POC
Leigh Business Enterprises Web HelpDesk SQL Injection Vulnerability
An exploit is not required, but a proof-of-concept script has been provided.
An exploit is not required, but a proof-of-concept script has been provided.
Solution / Fix
Leigh Business Enterprises Web HelpDesk SQL Injection Vulnerability
Solution:
The vendor has released version 4.0.0.81 addressing this issue.
Leigh Business Enterprises Web HelpDesk 4.0 .0.80
Solution:
The vendor has released version 4.0.0.81 addressing this issue.
Leigh Business Enterprises Web HelpDesk 4.0 .0.80
-
Leigh Business Enterprises weblatest.zip
Link to download the most current version of the software
http://www.lbehelpdesk.com/patch/web/weblatest.zip
References
Leigh Business Enterprises Web HelpDesk SQL Injection Vulnerability
References:
References:
- LBE Web HelpDesk SQL Injection (SecuriTeam)
- Web HelpDesk Changelog (Leigh Business Enterprises)
- Web HelpDesk Home Page (Leigh Business Enterprises)