thinkWMS Multiple SQL Injection Vulnerabilities
BID:18567
CVE-2006-3236 |Info
thinkWMS Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 18567 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2006 12:00AM |
| Updated: | Jun 21 2006 09:05PM |
| Credit: | r0t is credited with discovering these vulnerabilities. |
| Vulnerable: |
thinkfactory.de thinkWMS 1.0 |
| Not Vulnerable: | |
Discussion
thinkWMS Multiple SQL Injection Vulnerabilities
thinkWMS is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 1.0 and prior are reported to be vulnerable; other versions may also be affected.
thinkWMS is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions 1.0 and prior are reported to be vulnerable; other versions may also be affected.
Exploit / POC
thinkWMS Multiple SQL Injection Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
thinkWMS Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
thinkWMS Multiple SQL Injection Vulnerabilities
References:
References:
- thinkWMS SQL injection vuln. (r0t)
- thinkWMS Web Site (thinkfactory.de)