Secunia Advisory: SA29365  
Release Date: 2008-03-14

Critical:
Less critical
Impact: Manipulation of data
Where: From remote
Solution Status: Unpatched

Software:Virtual Support Office-XP 2.x

  This advisory is currently marked as unpatched!
- Companies can be alerted when a patch is released!
Description:
Aria-Security Team has reported a vulnerability in Virtual Support Office-XP (VSO-XP), which can be exploited by malicious users to conduct SQL injection attacks.

Input passed to the "Issue_ID" parameter in MyIssuesView.asp is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Solution:
Edit the source code to ensure that input is properly sanitised.

Provided and/or discovered by:
Aria-Security Team

Original Advisory:
http://forum.aria-security.com/showthread.php?p=21

資料來源 secunia.com/advisories/29365/
arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()