eBASEweb Unspecified SQL Injection Vulnerability
BID:15171
Info
eBASEweb Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 15171 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2005 12:00AM |
| Updated: | Oct 22 2005 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
eBASEweb eBASEweb 3.0 |
| Not Vulnerable: | |
Discussion
eBASEweb Unspecified SQL Injection Vulnerability
eBASEweb is prone to an unspecified SQL injecgtion vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
No further details have been provided.
eBASEweb is prone to an unspecified SQL injecgtion vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
No further details have been provided.
Exploit / POC
eBASEweb Unspecified SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
eBASEweb Unspecified SQL Injection Vulnerability
Solution:
The vendor has released an upgrade to fix issues in version 3.0; please see the references for further details.
eBASEweb eBASEweb 3.0
Solution:
The vendor has released an upgrade to fix issues in version 3.0; please see the references for further details.
eBASEweb eBASEweb 3.0
-
ebaseweb ebaseweb upgrade (Japanese)
http://www.ebase.co.jp/company/security/