Webmatic Multiple SQL Injection Vulnerabilities
BID:24878
Info
Webmatic Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 24878 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3648 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | The vendor reported these vulnerabilities. |
| Vulnerable: |
Valarsoft WebMatic 2.6.1 Valarsoft WebMatic 2.6 |
| Not Vulnerable: |
Valarsoft WebMatic 2.6.2 |
Discussion
Webmatic Multiple SQL Injection Vulnerabilities
Webmatic is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Webmatic 2.6.2 are vulnerable.
Webmatic is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Webmatic 2.6.2 are vulnerable.
Exploit / POC
Webmatic Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Webmatic Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released Webmatic 2.6.2 to address these issues.
Solution:
The vendor has released Webmatic 2.6.2 to address these issues.
References
Webmatic Multiple SQL Injection Vulnerabilities
References:
References:
- Webmatic Website (Webmatic)
- Webmatic: Webmatic 2.6.2 release (Valarsoft)