Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities
BID:17941
Info
Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities
| Bugtraq ID: | 17941 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2046 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2006 12:00AM |
| Updated: | May 15 2006 06:24PM |
| Credit: | r0t is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Application Dynamics, Inc. Cartweaver 2.16.11 |
| Not Vulnerable: |
Application Dynamics, Inc. Cartweaver 2.17.11 |
Discussion
Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities
Cartweaver ColdFusion is prone to SQL-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input before using it in SQL queries.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Cartweaver ColdFusion is prone to SQL-injection vulnerabilities. These issues are due to the application's failure to properly sanitize user-supplied input before using it in SQL queries.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities
These issues can be exploited through a web client.
Example URIs have been provided:
These issues can be exploited through a web client.
Example URIs have been provided:
Solution / Fix
Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities
Solution:
The vendor has released version 2.17.11 to address these issues; see the reference section for further information.
Solution:
The vendor has released version 2.17.11 to address these issues; see the reference section for further information.
References
Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities
References:
References:
- Cartweaver ColdFusion vuln. (r0t)
- Cartweaver Home Page (Application Dynamics, Inc.)