Macromedia Dreamweaver InterDev SQL Injection Vulnerability
BID:4714
Info
Macromedia Dreamweaver InterDev SQL Injection Vulnerability
| Bugtraq ID: | 4714 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2002 12:00AM |
| Updated: | May 10 2002 12:00AM |
| Credit: | Credited to Ross Overstreet <[email protected]>. |
| Vulnerable: |
Macromedia Dreamweaver Ultradev 4.0 Macromedia Dreamweaver 4.0 |
| Not Vulnerable: | |
Discussion
Macromedia Dreamweaver InterDev SQL Injection Vulnerability
ASP scripts generated by Dreamweaver/Interdev do not reportedly properly validate externally-supplied input when including HTML variables in SQL queries. Consequently, attackers may be able to modify any SQL queries performed by the application.
The existence of this vulnerability has not been confirmed by Macromedia.
ASP scripts generated by Dreamweaver/Interdev do not reportedly properly validate externally-supplied input when including HTML variables in SQL queries. Consequently, attackers may be able to modify any SQL queries performed by the application.
The existence of this vulnerability has not been confirmed by Macromedia.
Exploit / POC
Macromedia Dreamweaver InterDev SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Macromedia Dreamweaver InterDev SQL Injection Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Macromedia Dreamweaver InterDev SQL Injection Vulnerability
References:
References:
- Macromedia Homepage (Macromedia)