AAIPortal Unspecified SQL Injection Vulnerabilities
BID:20414
Info
AAIPortal Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 20414 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Oct 11 2006 03:54PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
AAIPortal AAIPortal 1.3.2 AAIPortal AAIPortal 1.2 AAIPortal AAIPortal 1.0.1 AAIPortal AAIPortal 0.9.6 |
| Not Vulnerable: |
AAIPortal AAIPortal 1.4 |
Discussion
AAIPortal Unspecified SQL Injection Vulnerabilities
AAIportal is prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
AAIportal 1.3.2 and prior versions are vulnerable to these issues.
AAIportal is prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
AAIportal 1.3.2 and prior versions are vulnerable to these issues.
Exploit / POC
AAIPortal Unspecified SQL Injection Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
AAIPortal Unspecified SQL Injection Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Solution:
The vendor has released an update to address these issues. Please see the references for more information.