Authenex ASAS Server 'username' Parameter SQL Injection Vulnerability
BID:49722
Info
Authenex ASAS Server 'username' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 49722 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4801 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2011 12:00AM |
| Updated: | Dec 15 2011 07:38PM |
| Credit: | Jose Carlos de Arriba of Foreground Security |
| Vulnerable: |
Authenex ASAS 3.1.0.3 Authenex ASAS 3.1.0.2 |
| Not Vulnerable: | |
Discussion
Authenex ASAS Server 'username' Parameter SQL Injection Vulnerability
Authenex ASAS server is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
This issue occurs on servers running End User Self Service (EUSS).
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ASAS 3.1.0.2 and 3.1.0.3 are vulnerable.
Authenex ASAS server is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
This issue occurs on servers running End User Self Service (EUSS).
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ASAS 3.1.0.2 and 3.1.0.3 are vulnerable.
Exploit / POC
Authenex ASAS Server 'username' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example input is available:
http://www.example.com/akeyActivationLogin.do
POST DATA: rgstcode=1111111111111111&username=a'; WAITFOR DELAY '0:0:30'--
Attackers can use a browser to exploit this issue.
The following example input is available:
http://www.example.com/akeyActivationLogin.do
POST DATA: rgstcode=1111111111111111&username=a'; WAITFOR DELAY '0:0:30'--
Solution / Fix
Authenex ASAS Server 'username' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Authenex ASAS Server 'username' Parameter SQL Injection Vulnerability
References:
References:
- Authenex A-Key/ASAS Web Management Control 3.1.0.2 - Time-based SQL Injection (FOREGROUND SECURITY)
- Authenex Homepage (Authenex)
- Security Bulletin AUTH11-001 - Important (Authenex)
- Security Bulletin AUTH11-001 - Important (Authenex)