Hummingbird CyberDOCS SQL Injection Vulnerability
BID:8800
Info
Hummingbird CyberDOCS SQL Injection Vulnerability
| Bugtraq ID: | 8800 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2003 12:00AM |
| Updated: | Oct 06 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to ProCheckUp. |
| Vulnerable: |
Hummingbird CyberDOCS 3.5.1 Hummingbird CyberDOCS 3.1 |
| Not Vulnerable: |
Hummingbird CyberDOCS 3.9 |
Discussion
Hummingbird CyberDOCS SQL Injection Vulnerability
Hummingbird CyberDOCS has been reported prone to an SQL Injection Vulnerability.
The issue has been reported to exist due to a lack of sufficient sanitization performed on user-supplied data that is parsed by the loginact.asp script.
Ultimately, an attacker may exploit this vulnerability to inject malicious SQL code into CyberDOCS SQL requests.
Hummingbird CyberDOCS has been reported prone to an SQL Injection Vulnerability.
The issue has been reported to exist due to a lack of sufficient sanitization performed on user-supplied data that is parsed by the loginact.asp script.
Ultimately, an attacker may exploit this vulnerability to inject malicious SQL code into CyberDOCS SQL requests.
Solution / Fix
References
Hummingbird CyberDOCS SQL Injection Vulnerability
References:
References:
- CyberDOCS Homepage (Hummingbird LTD.)
- Vulnerability Note VU#368300 (CERT/CC)