Netvolution 'referer' Header SQL Injection Vulnerability
BID:49918
Info
Netvolution 'referer' Header SQL Injection Vulnerability
| Bugtraq ID: | 49918 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3340 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2011 12:00AM |
| Updated: | Oct 03 2011 12:00AM |
| Credit: | Patroklos Argyroudis and Dimitris Glynos |
| Vulnerable: |
Netvolution Netvolution 2.5.8 |
| Not Vulnerable: | |
Discussion
Netvolution 'referer' Header SQL Injection Vulnerability
Netvolution is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Netvolution 2.5.8 is vulnerable; other versions may also be affected.
Netvolution is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Netvolution 2.5.8 is vulnerable; other versions may also be affected.
References
Netvolution 'referer' Header SQL Injection Vulnerability
References:
References:
- Atcom Homepage (Atcom)
- census: Netvolution referer header SQL injection vulnerability (census)
- Netvolution Homepage (Netvolution)