Multiple Symantec Products CVE-2014-7289 SQL Injection Vulnerability
BID:72092
Info
Multiple Symantec Products CVE-2014-7289 SQL Injection Vulnerability
| Bugtraq ID: | 72092 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7289 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2015 12:00AM |
| Updated: | Jan 19 2015 12:00AM |
| Credit: | Stefan Viehbock with SEC-Consult |
| Vulnerable: |
Symantec Data Center Security: Server Advanced Server 6.0 Symantec Critical System Protection 5.2.9 |
| Not Vulnerable: |
Symantec Data Center Security: Server Advanced Server 6.0.1 Symantec Critical System Protection 5.2.9 MP6 |
Discussion
Multiple Symantec Products CVE-2014-7289 SQL Injection Vulnerability
Multiple Symantec products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is fixed in the following versions:
Symantec Critical System Protection 5.2.9 MP6
Symantec Data Center Security: Server Advanced 6.0.1
Multiple Symantec products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is fixed in the following versions:
Symantec Critical System Protection 5.2.9 MP6
Symantec Data Center Security: Server Advanced 6.0.1
Exploit / POC
Multiple Symantec Products CVE-2014-7289 SQL Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
References
Multiple Symantec Products CVE-2014-7289 SQL Injection Vulnerability
References:
References: