Symantec IM Manager SQL Injection Vulnerability
BID:49738
Info
Symantec IM Manager SQL Injection Vulnerability
| Bugtraq ID: | 49738 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0553 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2011 12:00AM |
| Updated: | Mar 19 2015 09:11AM |
| Credit: | Sow Ching Shiong through Secunia Research |
| Vulnerable: |
Symantec IM Manager 8.4.16 Symantec IM Manager 8.4.15 Symantec IM Manager 8.4.13 Symantec IM Manager 8.4.12 Symantec IM Manager 8.4.11 Symantec IM Manager 8.4.10 Symantec IM Manager 8.4.9 Symantec IM Manager 8.4.8 Symantec IM Manager 8.4.7 Symantec IM Manager 8.4.6 Symantec IM Manager 8.4.5 Symantec IM Manager 8.4.2 Symantec IM Manager 8.4.1 Symantec IM Manager 8.4.17 Symantec IM Manager 8.4.0 Symantec IM Manager 8.4 |
| Not Vulnerable: |
Symantec IM Manager 8.4.18 |
Discussion
Symantec IM Manager SQL Injection Vulnerability
Symantec IM Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerability in the underlying database.
Versions prior to Symantec IM Manager 8.4.18 are vulnerable.
Symantec IM Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerability in the underlying database.
Versions prior to Symantec IM Manager 8.4.18 are vulnerable.
References
Symantec IM Manager SQL Injection Vulnerability
References:
References: