Enalean Tuleap CVE-2014-7176 SQL Injection Vulnerability
BID:70773
Info
Enalean Tuleap CVE-2014-7176 SQL Injection Vulnerability
| Bugtraq ID: | 70773 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7176 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2014 12:00AM |
| Updated: | Oct 28 2014 12:00AM |
| Credit: | Jerzy Kramarz |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Enalean Tuleap CVE-2014-7176 SQL Injection Vulnerability
Enalean Tuleap is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code, to gain elevated privileges and to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Enalean Tuleap 7.4.99.5 and prior are vulnerable.
Enalean Tuleap is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code, to gain elevated privileges and to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Enalean Tuleap 7.4.99.5 and prior are vulnerable.
Exploit / POC
Enalean Tuleap CVE-2014-7176 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example request is available:
GET /plugins/docman/?group_id=100&id=16&action=search&global_txt=a<SQL Injection>&global_filtersubmit=Apply HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://www.example.com/plugins/docman/?group_id=100
Cookie: PHPSESSID=3pt0ombsmp0t9adujgrohv8mb6; TULEAP_session_hash=d51433e1f7c9b49079c0e5c511d64c96
Connection: keep-alive
Attackers can use a browser to exploit this issue.
The following example request is available:
GET /plugins/docman/?group_id=100&id=16&action=search&global_txt=a<SQL Injection>&global_filtersubmit=Apply HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://www.example.com/plugins/docman/?group_id=100
Cookie: PHPSESSID=3pt0ombsmp0t9adujgrohv8mb6; TULEAP_session_hash=d51433e1f7c9b49079c0e5c511d64c96
Connection: keep-alive
Solution / Fix
Enalean Tuleap CVE-2014-7176 SQL Injection Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Enalean Tuleap CVE-2014-7176 SQL Injection Vulnerability
References:
References: