webSPELL SQL Injection and Open Email Relay Vulnerabilities
BID:43608
Info
webSPELL SQL Injection and Open Email Relay Vulnerabilities
| Bugtraq ID: | 43608 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2010 12:00AM |
| Updated: | Sep 30 2010 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
webSPELL webSPELL 4.2.1 webSPELL webSPELL 4.2 f webSPELL webSPELL 4.2 e webSPELL webSPELL 4.1.2 webSPELL webSPELL 4.1.1 webSPELL webSPELL 4.1 webSPELL webSPELL 4.2.0d webSPELL webSPELL 4.2.0c webSPELL webSPELL 4.0 |
| Not Vulnerable: |
webSPELL webSPELL 4.2.2a |
Discussion
webSPELL SQL Injection and Open Email Relay Vulnerabilities
webSPELL is prone to multiple SQL-injection vulnerabilities and an open-email-relay vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker could exploit these issues to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or to send unsolicited spam email to an unrestricted number of email addresses from a forged email address.
Versions prior to webSPELL 4.2.2a are vulnerable.
webSPELL is prone to multiple SQL-injection vulnerabilities and an open-email-relay vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker could exploit these issues to compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or to send unsolicited spam email to an unrestricted number of email addresses from a forged email address.
Versions prior to webSPELL 4.2.2a are vulnerable.
Exploit / POC
webSPELL SQL Injection and Open Email Relay Vulnerabilities
An attacker can exploit these issues through a browser.
An attacker can exploit these issues through a browser.
Solution / Fix
webSPELL SQL Injection and Open Email Relay Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
webSPELL SQL Injection and Open Email Relay Vulnerabilities
References:
References:
- webSPELL 4.2.2a Release (webSPELL)
- webSPELL Homepage (webSPELL)