Cyclope Employee Surveillance Solution Multiple Vulnerabilities
BID:55036
Info
Cyclope Employee Surveillance Solution Multiple Vulnerabilities
| Bugtraq ID: | 55036 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2012 12:00AM |
| Updated: | Aug 15 2012 12:00AM |
| Credit: | loneferret |
| Vulnerable: |
Amplusnet Cyclope Employee Surveillance Solution 6.2 Amplusnet Cyclope Employee Surveillance Solution 6.1 |
| Not Vulnerable: | |
Discussion
Cyclope Employee Surveillance Solution Multiple Vulnerabilities
Cyclope Employee Surveillance Solution is prone to multiple vulnerabilities.
1. A local file-include vulnerability
2. Multiple SQL-injection vulnerabilities
3. A security-bypass vulnerability
An attacker can exploit these issues to execute arbitrary local files within the context of the web server process, obtain sensitive information, compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Cyclope Employee Surveillance Solution 6.1.0 and 6.2.0 are vulnerable; other versions may also be affected.
Cyclope Employee Surveillance Solution is prone to multiple vulnerabilities.
1. A local file-include vulnerability
2. Multiple SQL-injection vulnerabilities
3. A security-bypass vulnerability
An attacker can exploit these issues to execute arbitrary local files within the context of the web server process, obtain sensitive information, compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Cyclope Employee Surveillance Solution 6.1.0 and 6.2.0 are vulnerable; other versions may also be affected.
Solution / Fix
Cyclope Employee Surveillance Solution Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].