GeoNetwork Opensource Login SQL Injection Vulnerability
BID:20671
Info
GeoNetwork Opensource Login SQL Injection Vulnerability
| Bugtraq ID: | 20671 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2006 12:00AM |
| Updated: | Oct 24 2006 05:03PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
GeoNetwork opensource 2.0.2 |
| Not Vulnerable: |
GeoNetwork opensource 2.0.3 |
Discussion
GeoNetwork Opensource Login SQL Injection Vulnerability
GeoNetwork opensource is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 2.0.2 and earlier.
GeoNetwork opensource is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects version 2.0.2 and earlier.
Exploit / POC
GeoNetwork Opensource Login SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
GeoNetwork Opensource Login SQL Injection Vulnerability
Solution:
The vendor has released version 2.0.3 to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released version 2.0.3 to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
References
GeoNetwork Opensource Login SQL Injection Vulnerability
References:
References:
- GeoNetwork Opensource Homepage (GeoNetwork)
- GeoNetwork Opensource v2.0.3 (GeoNetwork)