Orbit Open Ad Server '/guest/site_directory' SQL Injection Vulnerabilitiy
BID:66667
Info
Orbit Open Ad Server '/guest/site_directory' SQL Injection Vulnerabilitiy
| Bugtraq ID: | 66667 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2540 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2014 12:00AM |
| Updated: | Apr 17 2014 03:12AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Orbit Open Ad Server '/guest/site_directory' SQL Injection Vulnerabilitiy
Orbit Open Ad Server is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Orbit Open Ad Server 1.1.0 and prior are vulnerable.
Orbit Open Ad Server is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Orbit Open Ad Server 1.1.0 and prior are vulnerable.
Exploit / POC
Orbit Open Ad Server '/guest/site_directory' SQL Injection Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Orbit Open Ad Server '/guest/site_directory' SQL Injection Vulnerabilitiy
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Orbit Open Ad Server '/guest/site_directory' SQL Injection Vulnerabilitiy
References:
References: