|
Family: CGI abuses --> Category: attack
Help Center Live osTicket Module Multiple SQL Injection Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Tries to bypass authentication with a SQL injection attack
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application that is prone to
multiple SQL injection attacks.
Description :
The remote host is running Help Center Live, an open-source, web-based
help desk application written in PHP.
The version of Help Center Live installed on the remote host contains
a version of osTicket that is affected by multiple SQL injection
issues. An unauthenticated attacker may be able to leverage these
flaws to disclose sensitive information, modify data, bypass
authentication, or launch attacks against the underlying database.
See also :
http://sourceforge.net/project/shownotes.php?release_id=411859
Solution :
Upgrade to Help Center Live version 2.1.0 or later.
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|