Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
BID:16798
Info
Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
| Bugtraq ID: | 16798 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2006 12:00AM |
| Updated: | Mar 20 2006 11:39PM |
| Credit: | Remco Verhoef is credited with the discovery of this vulnerability. |
| Vulnerable: |
Virtual Communication Services VPMi 3.3 |
| Not Vulnerable: | |
Discussion
Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
VPMi Enterprise is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Note: Further information from the vendor indicates that this issue cannot be exploited to inject SQL. Note also that Symantec has not been able to reproduce the vulnerability.
VPMi Enterprise is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Note: Further information from the vendor indicates that this issue cannot be exploited to inject SQL. Note also that Symantec has not been able to reproduce the vulnerability.
Exploit / POC
Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
References
Virtual Communication Services VPMi Enterprise Service_Requests.ASP SQL Injection Vulnerability
References:
References:
- VPMi Web Site (Virtual Communication Services)