JBoss Seam 'order' Parameter SQL Injection Vulnerability
BID:26850
Info
JBoss Seam 'order' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 26850 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6433 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2007 12:00AM |
| Updated: | Apr 03 2008 05:49PM |
| Credit: | Antoni Jakubiak discovered this vulnerability. |
| Vulnerable: |
Redhat JBoss Enterprise Application Platform 4.2 EL4 JBoss Group JBoss Seam 2.0 CR3 JBoss Group JBoss Seam 2.0 CR2 JBoss Group JBoss Seam 2.0 CR1 |
| Not Vulnerable: |
JBoss Group JBoss Seam 2.0 GA |
Discussion
JBoss Seam 'order' Parameter SQL Injection Vulnerability
JBoss Seam is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise applications using the JBoss Seam framework, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects versions prior to JBoss Seam 2.0.0 GA.
JBoss Seam is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise applications using the JBoss Seam framework, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects versions prior to JBoss Seam 2.0.0 GA.
Exploit / POC
JBoss Seam 'order' Parameter SQL Injection Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
JBoss Seam 'order' Parameter SQL Injection Vulnerability
Solution:
The vendor has released JBoss Seam 2.0.0.GA to address this issue. Please see the references for more information.
JBoss Group JBoss Seam 2.0 CR2
JBoss Group JBoss Seam 2.0 CR3
JBoss Group JBoss Seam 2.0 CR1
Solution:
The vendor has released JBoss Seam 2.0.0.GA to address this issue. Please see the references for more information.
JBoss Group JBoss Seam 2.0 CR2
-
JBoss Group jboss-seam-2.0.0.GA.tar.gz
http://downloads.sourceforge.net/jboss/jboss-seam-2.0.0.GA.tar.gz?modt ime=1193930784&big_mirror=1
JBoss Group JBoss Seam 2.0 CR3
-
JBoss Group jboss-seam-2.0.0.GA.tar.gz
http://downloads.sourceforge.net/jboss/jboss-seam-2.0.0.GA.tar.gz?modt ime=1193930784&big_mirror=1
JBoss Group JBoss Seam 2.0 CR1
-
JBoss Group jboss-seam-2.0.0.GA.tar.gz
http://downloads.sourceforge.net/jboss/jboss-seam-2.0.0.GA.tar.gz?modt ime=1193930784&big_mirror=1
References
JBoss Seam 'order' Parameter SQL Injection Vulnerability
References:
References: