Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
BID:17676
Info
Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 17676 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2006 12:00AM |
| Updated: | Apr 24 2006 11:21PM |
| Credit: | The vendor reported these vulnerabilities. |
| Vulnerable: |
Help Center Live Help Center Live 2.0 Help Center Live Help Center Live 1.2.8 Help Center Live Help Center Live 1.2.7 Help Center Live Help Center Live 1.2.6 Help Center Live Help Center Live 1.2.5 Help Center Live Help Center Live 1.2.4 Help Center Live Help Center Live 1.2.3 Help Center Live Help Center Live 1.2.2 Help Center Live Help Center Live 1.2.1 Help Center Live Help Center Live 1.2 Help Center Live Help Center Live 1.0 |
| Not Vulnerable: |
Help Center Live Help Center Live 2.1 |
Discussion
Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
Help Center Live is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Help Center Live is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released version 2.1.0 to address this issue; please see the reference section for further details.
Help Center Live Help Center Live 1.0
Help Center Live Help Center Live 1.2
Help Center Live Help Center Live 1.2.1
Help Center Live Help Center Live 1.2.2
Help Center Live Help Center Live 1.2.3
Help Center Live Help Center Live 1.2.4
Help Center Live Help Center Live 1.2.5
Help Center Live Help Center Live 1.2.6
Help Center Live Help Center Live 1.2.7
Help Center Live Help Center Live 1.2.8
Help Center Live Help Center Live 2.0
Solution:
The vendor has released version 2.1.0 to address this issue; please see the reference section for further details.
Help Center Live Help Center Live 1.0
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.1
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.2
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.3
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.4
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.5
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.6
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.7
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 1.2.8
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
Help Center Live Help Center Live 2.0
-
Help Center Live hcl_2-1-0.zip
http://prdownloads.sourceforge.net/helpcenterlive/hcl_2-1-0.zip
References
Help Center Live OSTicket Module Multiple SQL Injection Vulnerabilities
References:
References:
- Help Center Live Home Page (Help Center Live)