Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
BID:15220
Info
Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 15220 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3315 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2005 12:00AM |
| Updated: | Oct 27 2005 12:00AM |
| Credit: | Dennis Rand at CIRT.DK is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Novell ZENworks Patch Management 6.0 .52 |
| Not Vulnerable: |
Novell ZENworks Patch Management 6.2 |
Discussion
Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
ZENworks Patch Management is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
It should be noted these vulnerabilities can only be exploited if a non-privileged account has been created. Only an administrator can create such an account.
ZENworks Patch Management is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
It should be noted these vulnerabilities can only be exploited if a non-privileged account has been created. Only an administrator can create such an account.
Exploit / POC
Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/computers/default.asp?sort=&Direction=';
http://www.example.com/reports/default.asp?sort=[ReportImpact_Name]&Dir=asc&SearchText=';StatusFilter=ERRR&computerFilter=187&impactFilter=29&saveFilter=save&Page=rep
http://www.example.com/reports/default.asp?sort=[ReportImpact_Name]&Dir=asc&SearchText=CIRT.DK&StatusFilter=';&computerFilter=187&impactFilter=29&saveFilter=save&Page=rep
http://www.example.com/reports/default.asp?sort=[ReportImpact_Name]&Dir=asc&SearchText=CIRT.DK&StatusFilter=ERRR&computerFilter=';&impactFilter=29&saveFilter=save&Page=rep
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/computers/default.asp?sort=&Direction=';
http://www.example.com/reports/default.asp?sort=[ReportImpact_Name]&Dir=asc&SearchText=';StatusFilter=ERRR&computerFilter=187&impactFilter=29&saveFilter=save&Page=rep
http://www.example.com/reports/default.asp?sort=[ReportImpact_Name]&Dir=asc&SearchText=CIRT.DK&StatusFilter=';&computerFilter=187&impactFilter=29&saveFilter=save&Page=rep
http://www.example.com/reports/default.asp?sort=[ReportImpact_Name]&Dir=asc&SearchText=CIRT.DK&StatusFilter=ERRR&computerFilter=';&impactFilter=29&saveFilter=save&Page=rep
Solution / Fix
Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
Solution:
The vendor has addressed these issues in ZENworks Patch Management version 6.2 and later:
Novell ZENworks Patch Management 6.0 .52
Solution:
The vendor has addressed these issues in ZENworks Patch Management version 6.2 and later:
Novell ZENworks Patch Management 6.0 .52
-
Novell ZEN_PatchMgmt_Upd6.2.iso
http://download.novell.com/Download?buildid=5_kRStyf9wU~
References
Novell ZENworks Patch Management Multiple SQL Injection Vulnerabilities
References:
References: