AContent SQL Injection and Authentication Bypass Vulnerabilities
BID:56237
Info
AContent SQL Injection and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 56237 |
| Class: | Unknown |
| CVE: |
CVE-2012-5454 CVE-2012-5453 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2012 12:00AM |
| Updated: | Oct 25 2012 12:00AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: |
ATutor AContent 1.1 |
| Not Vulnerable: | |
Discussion
AContent SQL Injection and Authentication Bypass Vulnerabilities
AContent is prone to an SQL-injection vulnerability and an authentication-bypass vulnerability.
An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, modify the logic of SQL queries, compromise the software, retrieve information, or modify data.
Note: These issues exist due to incomplete fixes for CVE-2012-5167 and CVE-2012-5168 (identified in BID 56100 - AContent Multiple Remote Security Vulnerabilities).
AContent is prone to an SQL-injection vulnerability and an authentication-bypass vulnerability.
An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, modify the logic of SQL queries, compromise the software, retrieve information, or modify data.
Note: These issues exist due to incomplete fixes for CVE-2012-5167 and CVE-2012-5168 (identified in BID 56100 - AContent Multiple Remote Security Vulnerabilities).
Exploit / POC
AContent SQL Injection and Authentication Bypass Vulnerabilities
Attackers can exploit these issues with a browser.
Attackers can exploit these issues with a browser.
Solution / Fix
AContent SQL Injection and Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AContent SQL Injection and Authentication Bypass Vulnerabilities
References:
References:
- AContent Product Page (atutor.com)
- Multiple vulnerabilities in AContent (High-Tech Bridge SA)