Vulnerability Bulletins |
Múltiples inyecciones SQL en Sciretech Multimedia Manager. |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio exotico |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software | Sciretech Multimedia Manager 3.x |
Description |
|
|
Se han descubierto múltiples vulnerabilidades de inyección SQL en Sciretech Multimedia Manager. La vulnerabilidad reside en los parámetros "dbuser_user_email" y "dbuser_user_password" en el fichero “index.php”. Un atacante remoto podría causar la inclusión de sentencias SQL mediante los parámetros afectados. |
|
Solution |
|
| De momento, no existe parche oficial para esta vulnerabilidad. Recomendamos visitar periódicamente la página web del proveedor. | |
Standar resources |
|
| Property | Value |
| CVE | |
| BID | |
Other resources |
|
|
Sciretech 3.0.0 SQL Injection / CSRF http://packetstormsecurity.org/files/116186/Sciretech-3.0.0-SQL-Injection-CSRF.html |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2012-09-04 |






