Virtualizor Unspecified SQL Injection Vulnerabilitiy
BID:61003
Info
Virtualizor Unspecified SQL Injection Vulnerabilitiy
| Bugtraq ID: | 61003 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2013 12:00AM |
| Updated: | Jun 24 2013 12:00AM |
| Credit: | RACK911 |
| Vulnerable: |
Softaculous Virtualizor 2.3 |
| Not Vulnerable: |
Softaculous Virtualizor 2.3.1 |
Discussion
Virtualizor Unspecified SQL Injection Vulnerabilitiy
Virtualizor is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Note: An attacker may escalate privileges to gain root access.
Virtualizor 2.3.0 is vulnerable; other versions may also be affected.
Virtualizor is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Note: An attacker may escalate privileges to gain root access.
Virtualizor 2.3.0 is vulnerable; other versions may also be affected.
Solution / Fix
Virtualizor Unspecified SQL Injection Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.