OTRS CVE-2014-1471 Unspecified SQL Injection Vulnerabilitiy
BID:65241
Info
OTRS CVE-2014-1471 Unspecified SQL Injection Vulnerabilitiy
| Bugtraq ID: | 65241 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1471 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 28 2014 12:00AM |
| Updated: | Feb 25 2014 03:53AM |
| Credit: | Karsten Nielsen |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
OTRS CVE-2014-1471 Unspecified SQL Injection Vulnerabilitiy
OTRS is prone to an unspecified SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
OTRS 3.3.x, 3.2.x, 3.1.x are vulnerable.
OTRS is prone to an unspecified SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
OTRS 3.3.x, 3.2.x, 3.1.x are vulnerable.
Exploit / POC
OTRS CVE-2014-1471 Unspecified SQL Injection Vulnerabilitiy
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
OTRS CVE-2014-1471 Unspecified SQL Injection Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.