IBM Algo One CVE-2013-6331 Unspecified SQL Injection Vulnerabilitiy
BID:65939
Info
IBM Algo One CVE-2013-6331 Unspecified SQL Injection Vulnerabilitiy
| Bugtraq ID: | 65939 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-6331 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2014 12:00AM |
| Updated: | Feb 28 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Algo One 5.0 IBM Algo One 4.9 IBM Algo One 4.8 IBM Algo One 4.7.1 IBM Algo One 4.7 IBM Algo One 4.9.1 |
| Not Vulnerable: | |
Discussion
IBM Algo One CVE-2013-6331 Unspecified SQL Injection Vulnerabilitiy
IBM Algo One is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
IBM Algo One is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
Exploit / POC
IBM Algo One CVE-2013-6331 Unspecified SQL Injection Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IBM Algo One CVE-2013-6331 Unspecified SQL Injection Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.