Raritan PowerIQ Multiple SQL Injection Vulnerabilities
BID:68722
Info
Raritan PowerIQ Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 68722 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9095 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2014 12:00AM |
| Updated: | Dec 03 2014 02:55AM |
| Credit: | Brandon Perry |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Raritan PowerIQ Multiple SQL Injection Vulnerabilities
Raritan PowerIQ is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Raritan PowerIQ 4.10 and 4.2.1 are vulnerable; other versions may also be affected.
Raritan PowerIQ is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Raritan PowerIQ 4.10 and 4.2.1 are vulnerable; other versions may also be affected.
Exploit / POC
Raritan PowerIQ Multiple SQL Injection Vulnerabilities
Attacker can exploit this issue with a browser.
The researcher who discovered these issues has created a proof of concept. Please see the references for more information.
Attacker can exploit this issue with a browser.
The researcher who discovered these issues has created a proof of concept. Please see the references for more information.
Solution / Fix
Raritan PowerIQ Multiple SQL Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Raritan PowerIQ Multiple SQL Injection Vulnerabilities
References:
References: