OpenDocMan Security Bypass and SQL Injection Vulnerabilities
BID:56912
Info
OpenDocMan Security Bypass and SQL Injection Vulnerabilities
| Bugtraq ID: | 56912 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2012 12:00AM |
| Updated: | Dec 12 2012 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenDocMan Security Bypass and SQL Injection Vulnerabilities
OpenDocMan is prone to a security-bypass vulnerability and an SQL-injection vulnerability.
An attacker can exploit these issues to bypass certain security restrictions and perform unauthorized actions, and compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OpenDocMan 1.2.6.2 is vulnerable; other versions may also be affected.
OpenDocMan is prone to a security-bypass vulnerability and an SQL-injection vulnerability.
An attacker can exploit these issues to bypass certain security restrictions and perform unauthorized actions, and compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OpenDocMan 1.2.6.2 is vulnerable; other versions may also be affected.