Covide Groupware-CRM Unspecified SQL Injection Vulnerability
BID:14156
Info
Covide Groupware-CRM Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 14156 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Jul 05 2005 12:00AM |
| Credit: | This vulnerability was announced by Hans Wolters <[email protected]>. |
| Vulnerable: |
Covide Groupware-CRM covide 5.2 |
| Not Vulnerable: | |
Discussion
Covide Groupware-CRM Unspecified SQL Injection Vulnerability
Covide Groupware-CRM is reportedly affected by an unspecified SQL injection vulnerability. This is due to the application failing to properly sanitize user-supplied input before being used in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Covide Groupware-CRM is reportedly affected by an unspecified SQL injection vulnerability. This is due to the application failing to properly sanitize user-supplied input before being used in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Covide Groupware-CRM Unspecified SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Covide Groupware-CRM Unspecified SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Covide Groupware-CRM Unspecified SQL Injection Vulnerability
References:
References:
- Covide Homepage (Covide Groupware-CRM)
- [covide] possible sql injection (Hans Wolters
)