Supportworks ITSM CVE-2013-2594 SQL Injection Vulnerability
BID:59439
Info
Supportworks ITSM CVE-2013-2594 SQL Injection Vulnerability
| Bugtraq ID: | 59439 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2594 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2013 12:00AM |
| Updated: | Apr 24 2013 12:00AM |
| Credit: | Joseph Sheridan of ReactionIS |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Supportworks ITSM CVE-2013-2594 SQL Injection Vulnerability
Supportworks ITSM is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Supportworks ITSM 1.0.0 is vulnerable; other versions may also be affected.
Supportworks ITSM is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Supportworks ITSM 1.0.0 is vulnerable; other versions may also be affected.
Exploit / POC
Supportworks ITSM CVE-2013-2594 SQL Injection Vulnerability
Attackers can exploit this issue using browser.
The following example URI is available:
http://www.example.com/reports/calldiary.php?callref=VULN
Attackers can exploit this issue using browser.
The following example URI is available:
http://www.example.com/reports/calldiary.php?callref=VULN
Solution / Fix
Supportworks ITSM CVE-2013-2594 SQL Injection Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Supportworks ITSM CVE-2013-2594 SQL Injection Vulnerability
References:
References: