Collabtive 'managefile.php' SQL Injection Vulnerability
BID:67287
Info
Collabtive 'managefile.php' SQL Injection Vulnerability
| Bugtraq ID: | 67287 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3246 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2014 12:00AM |
| Updated: | May 08 2014 12:00AM |
| Credit: | Deepak Rathore |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Collabtive 'managefile.php' SQL Injection Vulnerability
Collabtive is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Collabtive 1.2 is vulnerable; other versions may also be affected.
Collabtive is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Collabtive 1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Collabtive 'managefile.php' SQL Injection Vulnerability
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://example.com/collabtive-12/manageajax.php?action=fileview_list&id=2482&folder=1[SQL-injection]
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://example.com/collabtive-12/manageajax.php?action=fileview_list&id=2482&folder=1[SQL-injection]
Solution / Fix
Collabtive 'managefile.php' SQL Injection Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
Collabtive 'managefile.php' SQL Injection Vulnerability
References:
References:
- Collabtive Homepage (Collabtive)