Fortibus CMS Multiple SQL Injection Vulnerabilities
BID:14004
Info
Fortibus CMS Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 14004 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2005 12:00AM |
| Updated: | Jun 20 2005 12:00AM |
| Credit: | Discovery is credited to Tamer Hassan <[email protected]>. |
| Vulnerable: |
Fortibus Fortibus CMS 4.0 |
| Not Vulnerable: | |
Discussion
Fortibus CMS Multiple SQL Injection Vulnerabilities
Fortibus CMS is prone to multiple SQL injection vulnerabilities.
These issues could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Fortibus CMS 4.0 is vulnerable to these issues.
Fortibus CMS is prone to multiple SQL injection vulnerabilities.
These issues could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Fortibus CMS 4.0 is vulnerable to these issues.
Exploit / POC
Fortibus CMS Multiple SQL Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Fortibus CMS Multiple SQL Injection Vulnerabilities
Solution:
Reportedly, the vendor has released a patch to address this issue. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, the vendor has released a patch to address this issue. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.