Cisco Network Admission Control Manager CVE-2013-1177 SQL Injection Vulnerability
BID:59271
Info
Cisco Network Admission Control Manager CVE-2013-1177 SQL Injection Vulnerability
| Bugtraq ID: | 59271 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1177 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2013 12:00AM |
| Updated: | May 13 2013 11:12AM |
| Credit: | Nenad Stojanovski via ZDI |
| Vulnerable: |
Cisco Network Admission Control 4.9 Cisco Network Admission Control 4.8.2 Cisco Network Admission Control 4.8.1 Cisco Network Admission Control 4.8.0 |
| Not Vulnerable: | |
Discussion
Cisco Network Admission Control Manager CVE-2013-1177 SQL Injection Vulnerability
Cisco Network Admission Control Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database and execute arbitrary code.
This issue is tracked by Cisco BugID CSCub23095.
Cisco Network Admission Control Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database and execute arbitrary code.
This issue is tracked by Cisco BugID CSCub23095.
Exploit / POC
Cisco Network Admission Control Manager CVE-2013-1177 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Cisco Network Admission Control Manager CVE-2013-1177 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Network Admission Control Manager CVE-2013-1177 SQL Injection Vulnerability
References:
References: