Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilities
BID:11037
Info
Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilities
| Bugtraq ID: | 11037 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-2542 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2004 12:00AM |
| Updated: | Aug 24 2004 12:00AM |
| Credit: | Wil Allsopp <[email protected]> reported these vulnerabilities. |
| Vulnerable: |
Dynix WebPac 0 |
| Not Vulnerable: | |
Discussion
Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilities
It is reported that WebPac contains multiple undisclosed SQL injection vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data before using it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
This BID will be updated as further information is disclosed.
It is reported that WebPac contains multiple undisclosed SQL injection vulnerabilities. These vulnerabilities are due to a failure of the application to properly sanitize user-supplied input data before using it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
This BID will be updated as further information is disclosed.
Exploit / POC
Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilities
An exploit is likely not required.
An exploit is likely not required.
Solution / Fix
Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Dynix WebPac Multiple Undisclosed SQL Injection Vulnerabilities
References:
References:
- Dynix Home Page (Dynix)
- Dynix Webpac Input Validation (Wil Allsopp
)