Dell SonicWALL Scrutinizer Multiple SQL Injection Vulnerabilities
BID:57914
Info
Dell SonicWALL Scrutinizer Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 57914 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2013 12:00AM |
| Updated: | Feb 27 2013 06:13PM |
| Credit: | Benjamin Kunz Mejri |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Dell SonicWALL Scrutinizer Multiple SQL Injection Vulnerabilities
The Dell SonicWALL Scrutinizert is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Dell SonicWALL Scrutinizer 10.1.0 and prior versions are vulnerable.
The Dell SonicWALL Scrutinizert is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Dell SonicWALL Scrutinizer 10.1.0 and prior versions are vulnerable.
Exploit / POC
Dell SonicWALL Scrutinizer Multiple SQL Injection Vulnerabilities
An attacker can exploit these issues using a browser.
The following example URIs are available:
http://www.example.com/cgi-bin/fa_web.cgi?gadget=applicationsbytes-1%27[SQL]
http://www.example.com/cgi-bin/fa_web.cgi?gadget=applicationsbytes&orderby=-1%27[SQL]
An attacker can exploit these issues using a browser.
The following example URIs are available:
http://www.example.com/cgi-bin/fa_web.cgi?gadget=applicationsbytes-1%27[SQL]
http://www.example.com/cgi-bin/fa_web.cgi?gadget=applicationsbytes&orderby=-1%27[SQL]
Solution / Fix
Dell SonicWALL Scrutinizer Multiple SQL Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].