NullLogic Groupware Multiple Remote Vulnerabilities
BID:35606
Info
NullLogic Groupware Multiple Remote Vulnerabilities
| Bugtraq ID: | 35606 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2009 12:00AM |
| Updated: | Jul 09 2009 09:56PM |
| Credit: | Tim Brown |
| Vulnerable: |
NullLogic Groupware 1.2.7 |
| Not Vulnerable: | |
Discussion
NullLogic Groupware Multiple Remote Vulnerabilities
NullLogic Groupware is prone to the following remote vulnerabilities:
- An SQL-injection vulnerability
- A denial-of-service vulnerability
- A buffer-overflow vulnerability
Attackers can exploit these issues to compromise the affected application, execute arbitrary code within the context of the application, crash the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NullLogic Groupware 1.2.7 is vulnerable; other versions may also be affected.
NullLogic Groupware is prone to the following remote vulnerabilities:
- An SQL-injection vulnerability
- A denial-of-service vulnerability
- A buffer-overflow vulnerability
Attackers can exploit these issues to compromise the affected application, execute arbitrary code within the context of the application, crash the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NullLogic Groupware 1.2.7 is vulnerable; other versions may also be affected.
Exploit / POC
NullLogic Groupware Multiple Remote Vulnerabilities
An attacker can exploit the SQL-injection issue via a browser. The attacker can use readily available network utilities to exploit the denial-of-service issue.
Currently we are not aware of any working exploits for the buffer-overflow issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker can exploit the SQL-injection issue via a browser. The attacker can use readily available network utilities to exploit the denial-of-service issue.
Currently we are not aware of any working exploits for the buffer-overflow issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NullLogic Groupware Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NullLogic Groupware Multiple Remote Vulnerabilities
References:
References:
- NullLogic Groupware Homepage (NullLogic)