LogiSense Hawk-i Login SQL Injection Vulnerability
BID:4931
Info
LogiSense Hawk-i Login SQL Injection Vulnerability
| Bugtraq ID: | 4931 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0878 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovered by Akatosh <[email protected]>. |
| Vulnerable: |
LogiSense Hawk-i ASP LogiSense Hawk-i 5.2 LogiSense Hawk-i 4.5 LogiSense DNS Manager System |
| Not Vulnerable: | |
Discussion
LogiSense Hawk-i Login SQL Injection Vulnerability
LogiSense produces a range of web based billing and administration products. A vulnerability has been reported in the ASP based login process used by several of these products, including Hawk-i, Hawk-i ASP and DNS Manager System.
Reportedly, user input supplied as the login password is not adequately filtered. A malicious user may include special characters such as "'" in the supplied password and modify the SQL query used to validate the user. Access to arbitrary known accounts is possible.
This issue has been reported in current versions of LogiSense products. However, earlier versions may share this vulnerability.
LogiSense produces a range of web based billing and administration products. A vulnerability has been reported in the ASP based login process used by several of these products, including Hawk-i, Hawk-i ASP and DNS Manager System.
Reportedly, user input supplied as the login password is not adequately filtered. A malicious user may include special characters such as "'" in the supplied password and modify the SQL query used to validate the user. Access to arbitrary known accounts is possible.
This issue has been reported in current versions of LogiSense products. However, earlier versions may share this vulnerability.
Exploit / POC
LogiSense Hawk-i Login SQL Injection Vulnerability
Akatosh <[email protected]> has provided the following string, which should be used as the provided password: ' OR ''='
Akatosh <[email protected]> has provided the following string, which should be used as the provided password: ' OR ''='
Solution / Fix
LogiSense Hawk-i Login SQL Injection Vulnerability
Solution:
The vendor has released an advisory and has made fixes available.
LogiSense Hawk-i 4.5
LogiSense Hawk-i 5.2
Solution:
The vendor has released an advisory and has made fixes available.
LogiSense Hawk-i 4.5
-
LogiSense HawkiPatch45.EXE
http://www.logisense.com/HawkiPatch45.EXE
LogiSense Hawk-i 5.2
-
LogiSense HawkiPatch.EXE
http://www.logisense.com/HawkiPatch.EXE
References
LogiSense Hawk-i Login SQL Injection Vulnerability
References:
References:
- LogiSense Homepage (LogiSense)
- SQL Injection in LogiSense Software Solved (LogiSense)