IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
BID:4498
Info
IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
| Bugtraq ID: | 4498 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0555 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by Simon Lodal <[email protected]>. |
| Vulnerable: |
IBM Informix Web Datablade 4.13 IBM Informix Web Datablade 4.12 IBM Informix Web Datablade 4.11 IBM Informix Web Datablade 4.10 |
| Not Vulnerable: | |
Discussion
IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
Informix is an enterprise database distributed and maintained by IBM. The Web Datablade Module for Informix SQL dynamically generates HTML content based on Database data. Web Datablade is available for Apache, IIS, and Netscape web servers, and a generic CGI version is provided for alternative servers. It will execute under Windows NT, Linux and many Unix-like systems.
Reportedly, SQL queries executed by Web Datablade decode HTML encoded input. If a developer were to use HTML encoding to sanitize user input, it would be possible to inadvertently create insecure applications.
Informix is an enterprise database distributed and maintained by IBM. The Web Datablade Module for Informix SQL dynamically generates HTML content based on Database data. Web Datablade is available for Apache, IIS, and Netscape web servers, and a generic CGI version is provided for alternative servers. It will execute under Windows NT, Linux and many Unix-like systems.
Reportedly, SQL queries executed by Web Datablade decode HTML encoded input. If a developer were to use HTML encoding to sanitize user input, it would be possible to inadvertently create insecure applications.
Exploit / POC
IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
Solution:
The vendor does not consider this to be a bug and as such, there is no fix available.
Solution:
The vendor does not consider this to be a bug and as such, there is no fix available.
References
IBM Informix Web Datablade SQL Query HTML Decoding Vulnerability
References:
References: