EMC Secure Remote Services Virtual Edition CVE-2015-0524 Unspecified SQL Injection Vulnerability
BID:73023
Info
EMC Secure Remote Services Virtual Edition CVE-2015-0524 Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 73023 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-0524 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2015 12:00AM |
| Updated: | Mar 11 2015 12:00AM |
| Credit: | Han Sahin of Securify B.V. |
| Vulnerable: |
EMC EMC Secure Remote Services Virtual Edition 3.03 EMC EMC Secure Remote Services Virtual Edition 3.02 |
| Not Vulnerable: |
EMC EMC Secure Remote Services Virtual Edition 3.04 |
Discussion
EMC Secure Remote Services Virtual Edition CVE-2015-0524 Unspecified SQL Injection Vulnerability
EMC Secure Remote Services Virtual Edition is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are vulnerable:
EMC Secure Remote Services Virtual Edition 3.02
EMC Secure Remote Services Virtual Edition 3.03
EMC Secure Remote Services Virtual Edition is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are vulnerable:
EMC Secure Remote Services Virtual Edition 3.02
EMC Secure Remote Services Virtual Edition 3.03
References
EMC Secure Remote Services Virtual Edition CVE-2015-0524 Unspecified SQL Injection Vulnerability
References:
References: