Interact 'email_user_key' Parameter SQL Injection Vulnerability
BID:32014
Info
Interact 'email_user_key' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 32014 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3867 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Nov 03 2008 11:35PM |
| Credit: | Secunia Research |
| Vulnerable: |
Interact Learning Community Environment Interact 2.4.1 |
| Not Vulnerable: | |
Discussion
Interact 'email_user_key' Parameter SQL Injection Vulnerability
Interact is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Interact 2.4.1 is vulnerable; other versions may also be affected.
Interact is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Interact 2.4.1 is vulnerable; other versions may also be affected.
Exploit / POC
Interact 'email_user_key' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Interact 'email_user_key' Parameter SQL Injection Vulnerability
Solution:
The vendor released a patch. Please see the references for more information.
Solution:
The vendor released a patch. Please see the references for more information.
References
Interact 'email_user_key' Parameter SQL Injection Vulnerability
References:
References:
- [ 2208205 ] Security patch for 2.4.1 (Glen Davies)
- Interact SourceForge Page (Interact Learning Community Environment)
- Secunia Research: Interact SQL Injection and Cross-Site Request Forgery (Secunia Research
) - Secunia Research: Interact SQL Injection and Cross-Site Request Forgery (Secunia)