Open-Xchange AppSuite 'ExtractValue()' Function SQL Injection Vulnerability
BID:70982
Info
Open-Xchange AppSuite 'ExtractValue()' Function SQL Injection Vulnerability
| Bugtraq ID: | 70982 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7871 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2014 12:00AM |
| Updated: | Nov 07 2014 12:00AM |
| Credit: | Martin Heiland |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Open-Xchange AppSuite 'ExtractValue()' Function SQL Injection Vulnerability
Open-Xchange AppSuite is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Open-Xchange AppSuite 7.6.0 and prior are vulnerable.
Open-Xchange AppSuite is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Open-Xchange AppSuite 7.6.0 and prior are vulnerable.
Exploit / POC
Open-Xchange AppSuite 'ExtractValue()' Function SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Open-Xchange AppSuite 'ExtractValue()' Function SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Open-Xchange AppSuite 'ExtractValue()' Function SQL Injection Vulnerability
References:
References: