Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability
BID:16452
Info
Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability
| Bugtraq ID: | 16452 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0522 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2006 12:00AM |
| Updated: | Jun 27 2007 06:48PM |
| Credit: | Discovered by Guillaume Goutaudier. |
| Vulnerable: |
Symantec Sygate Management Server Japanese Version 4.1 GA build 1258 Symantec Sygate Management Server English version 4.1 MR 2 build 1417 Symantec Sygate Management Server English version 4.0 MR 1 build 1104 Symantec Sygate Management Server English version 3.5 MR 3 build 894 Symantec Sygate Management Server Chinese Version 4.1 MR1 build 1351 |
| Not Vulnerable: | |
Discussion
Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability
Symantec Sygate Management Server is prone to an SQL-injection vulnerability.
The vulnerability specifically affects the SMS Authentication Servlet component of the server.
A remote attacker can pass malicious input to database queries through HTTP GET requests, resulting in modification of query logic or other attacks.
This issue can allow attackers to overwrite the password of any account on the server. This can facilitate a complete compromise if the attacker can overwrite the administrator password.
Symantec Sygate Management Server is prone to an SQL-injection vulnerability.
The vulnerability specifically affects the SMS Authentication Servlet component of the server.
A remote attacker can pass malicious input to database queries through HTTP GET requests, resulting in modification of query logic or other attacks.
This issue can allow attackers to overwrite the password of any account on the server. This can facilitate a complete compromise if the attacker can overwrite the administrator password.
Exploit / POC
Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability
An exploit is not required.
A proof of concept is available.
An exploit is not required.
A proof of concept is available.
Solution / Fix
Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability
Solution:
Symantec has released SYM06-002 to address this issue. Please see the referenced advisory for more information.
The Japanese version of SMS is distributed through Macnica Inc. Customers are advised to contact their Macnica Support representative to obtain the update.
Solution:
Symantec has released SYM06-002 to address this issue. Please see the referenced advisory for more information.
The Japanese version of SMS is distributed through Macnica Inc. Customers are advised to contact their Macnica Support representative to obtain the update.
References
Symantec Sygate Management Server SMS Authentication Servlet SQL Injection Vulnerability
References:
References: