Help Request System Unspecified SQL Injection Vulnerability
BID:49430
Info
Help Request System Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 49430 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2011 12:00AM |
| Updated: | Sep 02 2011 12:00AM |
| Credit: | Positive Research |
| Vulnerable: |
Help Request System Help Request System 1.1A |
| Not Vulnerable: |
Help Request System Help Request System 1.1g |
Discussion
Help Request System Unspecified SQL Injection Vulnerability
Help Request System is prone to an unspecified SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Help Request System 1.1a and prior are vulnerable.
Help Request System is prone to an unspecified SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Help Request System 1.1a and prior are vulnerable.
Exploit / POC
Help Request System Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Help Request System Unspecified SQL Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Help Request System Unspecified SQL Injection Vulnerability
References:
References: