Cybozu Garoon CVE-2013-0701 Unspecified SQL Injection Vulnerabilitiy
BID:57866
Info
Cybozu Garoon CVE-2013-0701 Unspecified SQL Injection Vulnerabilitiy
| Bugtraq ID: | 57866 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0701 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2013 12:00AM |
| Updated: | Feb 08 2013 12:00AM |
| Credit: | Ken Asai |
| Vulnerable: |
Cybozu Garoon 2.5.0 |
| Not Vulnerable: | |
Discussion
Cybozu Garoon CVE-2013-0701 Unspecified SQL Injection Vulnerabilitiy
Cybozu Garoon is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
Cybozu Garoon versions 2.5.0 through 3.5.3 are vulnerable.
Cybozu Garoon is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
Cybozu Garoon versions 2.5.0 through 3.5.3 are vulnerable.
Exploit / POC
Cybozu Garoon CVE-2013-0701 Unspecified SQL Injection Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Cybozu Garoon CVE-2013-0701 Unspecified SQL Injection Vulnerabilitiy
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cybozu Garoon CVE-2013-0701 Unspecified SQL Injection Vulnerabilitiy
References:
References:
- Cybozu Garoon Download page (Cybozu)
- JVN#07629635 Cybozu Garoon vulnerable to SQL injection (JPCERT/CC)