Symantec LiveUpdate Administrator CVE-2014-1645 SQL Injection Vulnerability
BID:66400
Info
Symantec LiveUpdate Administrator CVE-2014-1645 SQL Injection Vulnerability
| Bugtraq ID: | 66400 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1645 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2014 12:00AM |
| Updated: | Apr 02 2014 01:06AM |
| Credit: | Stefan Viehböck from SEC Consult Vulnerability Lab |
| Vulnerable: |
Symantec LiveUpdate Administrator 2.3 Symantec LiveUpdate Administrator 2.2.2.9 |
| Not Vulnerable: | |
Discussion
Symantec LiveUpdate Administrator CVE-2014-1645 SQL Injection Vulnerability
Symantec LiveUpdate Administrator is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec LiveUpdate Administrator 2.3.2 and prior are vulnerable.
Symantec LiveUpdate Administrator is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symantec LiveUpdate Administrator 2.3.2 and prior are vulnerable.
Exploit / POC
Symantec LiveUpdate Administrator CVE-2014-1645 SQL Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Symantec LiveUpdate Administrator CVE-2014-1645 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec LiveUpdate Administrator CVE-2014-1645 SQL Injection Vulnerability
References:
References:
- Symantec Homepage (Symantec)