Novell ZENWorks Asset Management 'documentID' Parameter SQL Injection Vulnerability
BID:37764
Info
Novell ZENWorks Asset Management 'documentID' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 37764 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2010 12:00AM |
| Updated: | Jan 20 2010 10:32PM |
| Credit: | An anonymous researcher |
| Vulnerable: |
Novell ZENworks Asset Management 7.5 |
| Not Vulnerable: |
Novell ZENworks Asset Management 7.5 IR19 Interim Rel |
Discussion
Novell ZENWorks Asset Management 'documentID' Parameter SQL Injection Vulnerability
Novell ZENWorks Asset Management is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Novell ZENWorks Asset Management 7.5 is vulnerable; other versions may be affected as well.
Novell ZENWorks Asset Management is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Novell ZENWorks Asset Management 7.5 is vulnerable; other versions may be affected as well.
Exploit / POC
Novell ZENWorks Asset Management 'documentID' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Novell ZENWorks Asset Management 'documentID' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Novell ZENWorks Asset Management 'documentID' Parameter SQL Injection Vulnerability
References:
References:
- Novell ZENworks Asset Management docfiledownload Remote SQL Injection Vulnerabil (TippingPoint Zero Day Initiative)
- ZENworks Asset Management Homepage (Novell)
- 7005128 ZAM 7.5 SQLinfection Vulnerability (Novell)