Polycom HDX Series SQL Injection Vulnerability
BID:58526
Info
Polycom HDX Series SQL Injection Vulnerability
| Bugtraq ID: | 58526 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2013 12:00AM |
| Updated: | Mar 15 2013 12:00AM |
| Credit: | Moritz Jodeit of n.runs AG |
| Vulnerable: |
Polycom HDX 9000 0 Polycom HDX 8000 0 Polycom HDX 7000 0 Polycom HDX 6000 0 Polycom HDX 4000 0 |
| Not Vulnerable: |
Polycom HDX 9000 3.1.1 2 Polycom HDX 8000 3.1.1 2 Polycom HDX 7000 3.1.1 2 Polycom HDX 6000 3.1.1 2 Polycom HDX 4000 3.1.1 2 |
Discussion
Polycom HDX Series SQL Injection Vulnerability
Polycom HDX Series devices are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an authenticated attacker to compromise the affected device, access or modify data, or exploit latent vulnerabilities in the underlying database.
Polycom HDX Series devices are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an authenticated attacker to compromise the affected device, access or modify data, or exploit latent vulnerabilities in the underlying database.
Solution / Fix
Polycom HDX Series SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.