Apache::AuthCAS Cookie SQL Injection Vulnerability
BID:26762
Info
Apache::AuthCAS Cookie SQL Injection Vulnerability
| Bugtraq ID: | 26762 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6342 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2007 12:00AM |
| Updated: | Mar 24 2008 08:10PM |
| Credit: | Matthias Bethke is credited with the discovery of this vulnerability. |
| Vulnerable: |
David Castro Apache::AuthCAS 0.4 |
| Not Vulnerable: | |
Discussion
Apache::AuthCAS Cookie SQL Injection Vulnerability
Apache::AuthCAS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects Apache::AuthCAS 0.4; other versions may also be affected.
Apache::AuthCAS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects Apache::AuthCAS 0.4; other versions may also be affected.
Exploit / POC
Apache::AuthCAS Cookie SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Apache::AuthCAS Cookie SQL Injection Vulnerability
Solution:
The vendor has released a fix. Please see the references for more information.
Solution:
The vendor has released a fix. Please see the references for more information.
References
Apache::AuthCAS Cookie SQL Injection Vulnerability
References:
References: