EMC Centera Universal Access 'username' Parameter SQL Injection Vulnerability
BID:30358
Info
EMC Centera Universal Access 'username' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 30358 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3370 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2008 12:00AM |
| Updated: | May 07 2015 05:25PM |
| Credit: | Lars Heidelberg and Aaron Brown of adMERITia GmbH |
| Vulnerable: |
EMC Centera Universal Access 4.0_4735.p4 |
| Not Vulnerable: |
EMC Centera Universal Access 4.0.1 Patch 1 |
Discussion
EMC Centera Universal Access 'username' Parameter SQL Injection Vulnerability
EMC Centera Universal Access (CUA) is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CUA 4.0_4735.p4 is vulnerable; other versions may also be affected.
EMC Centera Universal Access (CUA) is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CUA 4.0_4735.p4 is vulnerable; other versions may also be affected.
Exploit / POC
EMC Centera Universal Access 'username' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
Username: valid_user_name
Password: --
Attackers can use a browser to exploit this issue.
The following proof of concept is available:
Username: valid_user_name
Password: --
Solution / Fix
EMC Centera Universal Access 'username' Parameter SQL Injection Vulnerability
Solution:
Reports indicate that this issue has been addressed in CUA 4.0.1 Patch 1. Please contact the vendor for information on how to obtain and apply this update.
Solution:
Reports indicate that this issue has been addressed in CUA 4.0.1 Patch 1. Please contact the vendor for information on how to obtain and apply this update.
References
EMC Centera Universal Access 'username' Parameter SQL Injection Vulnerability
References:
References:
- EMC Centera Universal Access Homepage (EMC)
- Vulnerability Report: EMC Centera Universal Access (Aaron Brown, adMERITia GmbH)