ownCloud 'lib/db.php' Script CVE-2013-2045 SQL Injection Vulnerability
BID:59961
Info
ownCloud 'lib/db.php' Script CVE-2013-2045 SQL Injection Vulnerability
| Bugtraq ID: | 59961 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2045 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2013 12:00AM |
| Updated: | May 14 2013 12:00AM |
| Credit: | Mateusz Goik |
| Vulnerable: |
ownCloud ownCloud 5.0.5 ownCloud ownCloud 5.0.4 ownCloud ownCloud 5.0.3 ownCloud ownCloud 5.0.1 ownCloud ownCloud 5.0 ownCloud ownCloud 4.5.11 ownCloud ownCloud 4.5.10 ownCloud ownCloud 4.5.9 ownCloud ownCloud 4.5.8 ownCloud ownCloud 4.5.7 ownCloud ownCloud 4.5.2 ownCloud ownCloud 4.5 ownCloud ownCloud 4.0.15 ownCloud ownCloud 4.0.14 ownCloud ownCloud 4.0.13 ownCloud ownCloud 4.0.12 ownCloud ownCloud 4.0.9 ownCloud ownCloud 4.0.7 ownCloud ownCloud 4.0.6 ownCloud ownCloud 4.0.5 ownCloud ownCloud 4.0.4 ownCloud ownCloud 4.5.6 ownCloud ownCloud 4.5.5 ownCloud ownCloud 4.0.3 ownCloud ownCloud 4.0.2 ownCloud ownCloud 4.0.11 ownCloud ownCloud 4.0.10 ownCloud ownCloud 4.0.1 ownCloud ownCloud 3.0.2 ownCloud ownCloud 3.0.1 ownCloud ownCloud 3.0.0 |
| Not Vulnerable: |
ownCloud ownCloud 5.0.6 |
Discussion
ownCloud 'lib/db.php' Script CVE-2013-2045 SQL Injection Vulnerability
ownCloud is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Note: This issue was previously discussed in BID 59875 (ownCloud Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
Versions prior to ownCloud 5.0.6 are vulnerable.
ownCloud is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Note: This issue was previously discussed in BID 59875 (ownCloud Multiple Security Vulnerabilities), but has been moved to its own record for better documentation.
Versions prior to ownCloud 5.0.6 are vulnerable.
Exploit / POC
ownCloud 'lib/db.php' Script CVE-2013-2045 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
ownCloud 'lib/db.php' Script CVE-2013-2045 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.