eTicket Input Validation Flaw in 'pri' Parameter Lets Remote Users Inject SQL Commands
|
|
SecurityTracker Alert ID: 1020379
|
|
SecurityTracker URL: http://securitytracker.com/id?1020379
|
|
CVE Reference: CVE-2008-5165
(Links to External Site)
|
Updated: Mar 14 2009
|
Original Entry Date: Jun 27 2008
|
Impact: Disclosure of system information, Disclosure of user information, User access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 1.7.0
|
Description: A vulnerability was reported in eTicket. A remote user can inject SQL commands.
The software does not properly validate user-supplied input in the 'pri' parameter. A remote user can supply a specially crafted
parameter value to execute SQL commands on the underlying database.
The 'index.php', 'open.php', 'open_raw.php', and 'newticket.php'
pages are affected.
The original advisory is available at:
http://www.digitrustgroup.com/advisories/web-application-security-eticket2.html
Omer
Singer of the DigiTrust Group reported this vulnerability.
|
Impact: A remote user can execute SQL commands on the underlying database.
|
Solution: The vendor has issued a fixed version (1.7.0).
The vendor's advisory is available at:
http://www.eticketsupport.com/announcements/170_is_in_the_building-t91.0.html
|
Vendor URL: eticket.sourceforge.net/ (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 27 Jun 2008 13:14:03 -0400
Subject: eTicket
|
http://www.digitrustgroup.com/advisories/web-application-security-eticket2.html
|
|