ManageEngine ServiceDesk Plus 'CreateReportTable.jsp' SQL Injection Vulnerability
BID:72299
Info
ManageEngine ServiceDesk Plus 'CreateReportTable.jsp' SQL Injection Vulnerability
| Bugtraq ID: | 72299 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-1479 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2015 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Rewterz - Research Group |
| Vulnerable: |
ManageEngine ServiceDesk Plus 9.0 |
| Not Vulnerable: |
ManageEngine ServiceDesk Plus 9.0 Build 9031 |
Discussion
ManageEngine ServiceDesk Plus 'CreateReportTable.jsp' SQL Injection Vulnerability
ManageEngine ServiceDesk Plus is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ManageEngine ServiceDesk Plus 9.0 is vulnerable; other versions may also be affected.
ManageEngine ServiceDesk Plus is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ManageEngine ServiceDesk Plus 9.0 is vulnerable; other versions may also be affected.
Exploit / POC
ManageEngine ServiceDesk Plus 'CreateReportTable.jsp' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
www.example.com/reports/CreateReportTable.jsp?site=0 AND3133=(SELECT 3133 FROM PG_SLEEP(1))
Attackers can use a browser to exploit this issue.
The following example URI is available:
www.example.com/reports/CreateReportTable.jsp?site=0 AND3133=(SELECT 3133 FROM PG_SLEEP(1))
Solution / Fix
ManageEngine ServiceDesk Plus 'CreateReportTable.jsp' SQL Injection Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
ManageEngine ServiceDesk Plus 'CreateReportTable.jsp' SQL Injection Vulnerability
References:
References:
- ServiceDesk Plus Homepage (ManageEngine)
- [REWTERZ-20140101] �?? Rewterz �?? Security Advisory (rewterz)