Microsoft Content Management Server 2001 SQL Injection Vulnerability
BID:5422
Info
Microsoft Content Management Server 2001 SQL Injection Vulnerability
| Bugtraq ID: | 5422 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2002 12:00AM |
| Updated: | Aug 07 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Joao Gouveia <[email protected]>. |
| Vulnerable: |
Microsoft Content Management Server 2001 SP1 Microsoft Content Management Server 2001 |
| Not Vulnerable: | |
Discussion
Microsoft Content Management Server 2001 SQL Injection Vulnerability
Microsoft Content Management Server (MCMS) 2001 is a .NET Enterprise Server
product for development and management of e-business websites.
MCMS allows users and web pages to request files from the database. The user input for these requests is not properly sanitized by MCMS, allowing the user to insert SQL code. Execution of operating system commands is also possible.
Microsoft Content Management Server (MCMS) 2001 is a .NET Enterprise Server
product for development and management of e-business websites.
MCMS allows users and web pages to request files from the database. The user input for these requests is not properly sanitized by MCMS, allowing the user to insert SQL code. Execution of operating system commands is also possible.
Solution / Fix
Microsoft Content Management Server 2001 SQL Injection Vulnerability
Solution:
Microsoft has released a patch to address this issue:
Microsoft Content Management Server 2001
Microsoft Content Management Server 2001 SP1
Solution:
Microsoft has released a patch to address this issue:
Microsoft Content Management Server 2001
-
Microsoft mcms2001srp1.exe
http://download.microsoft.com/download/contentmanagementser/SP/1.0/NT5 /EN-US/mcms2001srp1.exe
Microsoft Content Management Server 2001 SP1
-
Microsoft mcms2001srp1.exe
http://download.microsoft.com/download/contentmanagementser/SP/1.0/NT5 /EN-US/mcms2001srp1.exe
References
Microsoft Content Management Server 2001 SQL Injection Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-041 (Microsoft)