ELBA Multiple Remote Security Vulnerabilities
BID:57013
Info
ELBA Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 57013 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2012 12:00AM |
| Updated: | Dec 20 2012 12:00AM |
| Credit: | Kestutis Gudinavicius, SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ELBA Multiple Remote Security Vulnerabilities
ELBA is prone to multiple information-disclosure vulnerabilities, an SQL-injection vulnerability and a stack-based buffer-overflow vulnerability.
An attacker can exploit these vulnerabilities to disclose sensitive information, exploit latent vulnerabilities in the underlying database, or execute arbitrary code in the context of the user running the affected application. Other attacks are also possible.
ELBA 5.5.0 R00006 build 0796 is vulnerable; other versions may also be affected.
ELBA is prone to multiple information-disclosure vulnerabilities, an SQL-injection vulnerability and a stack-based buffer-overflow vulnerability.
An attacker can exploit these vulnerabilities to disclose sensitive information, exploit latent vulnerabilities in the underlying database, or execute arbitrary code in the context of the user running the affected application. Other attacks are also possible.
ELBA 5.5.0 R00006 build 0796 is vulnerable; other versions may also be affected.
Exploit / POC
ELBA Multiple Remote Security Vulnerabilities
An attacker can exploit these issues through a browser.
An attacker can exploit these issues through a browser.
References
ELBA Multiple Remote Security Vulnerabilities
References:
References:
- ELBA Homepage (RACON Software GmbH Linz)
- Multiple Vulnerabilities in ELBA5 (Kestutis Gudinavicius)