Ecava IntegraXor Unspecified SQL Injection Vulnerability
BID:47019
Info
Ecava IntegraXor Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 47019 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1562 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2011 12:00AM |
| Updated: | Apr 11 2011 11:35AM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
Ecava IntegraXor 3.60.4032 Ecava IntegraXor 3.60 Ecava IntegraXor 3.6.4000.0 Ecava IntegraXor 3.5.3900.5 Ecava IntegraXor 3.5.3900.10 Ecava IntegraXor 3.5 |
| Not Vulnerable: |
Ecava IntegraXor 3.60.4050 Ecava IntegraXor 3.6.4000.5 |
Discussion
Ecava IntegraXor Unspecified SQL Injection Vulnerability
Ecava IntegraXor is prone to an unspecified SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to IntegraXor 3.60.4050 are vulnerable.
Ecava IntegraXor is prone to an unspecified SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to IntegraXor 3.60.4050 are vulnerable.
Exploit / POC
Ecava IntegraXor Unspecified SQL Injection Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Ecava IntegraXor Unspecified SQL Injection Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Ecava IntegraXor Unspecified SQL Injection Vulnerability
References:
References: