Hitachi EUR Unspecified SQL Injection Vulnerability
BID:18015
CVE-2006-2512 |Info
Hitachi EUR Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 18015 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2006 12:00AM |
| Updated: | May 17 2006 09:54PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Hitachi EUR Viewer 05-06 Hitachi EUR Viewer 05-00 Hitachi EUR Professional 05-06 Hitachi EUR Professional 05-00 Hitachi EUR Print Service for ILF 05-06 Hitachi EUR Print Service 05-06 Hitachi EUR Print Service 05-01 |
| Not Vulnerable: |
Hitachi EUR Viewer 05-06-/A Hitachi EUR Professional 05-06-/A Hitachi EUR Print Service 05-06-/A |
Discussion
Hitachi EUR Unspecified SQL Injection Vulnerability
Hitachi EUR is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
Hitachi EUR is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Hitachi EUR Unspecified SQL Injection Vulnerability
This issue can be exploited with a web client.
This issue can be exploited with a web client.
Solution / Fix
Hitachi EUR Unspecified SQL Injection Vulnerability
Solution:
The vendor has released updated versions to address this issue. See the referenced advisory for further information.
Solution:
The vendor has released updated versions to address this issue. See the referenced advisory for further information.
References
Hitachi EUR Unspecified SQL Injection Vulnerability
References:
References:
- Hitachi Home Page (Hitachi)
- HS06-010 - SQL Injection Vulnerability in EUR (Hitachi)