Pentaho BI Project Multiple Unspecified SQL Injection Vulnerabilities
BID:20806
Info
Pentaho BI Project Multiple Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 20806 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2006 12:00AM |
| Updated: | Oct 31 2006 05:02PM |
| Credit: | These issues were disclosed by the vendor. |
| Vulnerable: |
Pentaho BI 1.2 RC2 |
| Not Vulnerable: |
Pentaho BI 1.2 RC3 |
Discussion
Pentaho BI Project Multiple Unspecified SQL Injection Vulnerabilities
Pentaho BI Project is prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Pentaho BI Project is prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Pentaho BI Project Multiple Unspecified SQL Injection Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Pentaho BI Project Multiple Unspecified SQL Injection Vulnerabilities
Solution:
The vendor addressed these issues in version 1.2 RC3.
Solution:
The vendor addressed these issues in version 1.2 RC3.
References
Pentaho BI Project Multiple Unspecified SQL Injection Vulnerabilities
References:
References:
- Pentaho Homepage (Pentaho)
- Stable Build - Release Candidate 3 (ver. 1.2.0 RC3) Release Notes (Pentaho)