Vulnerabilidad de SQL Injection en ZAPms
|
Vulnerability classification
|
|
Property |
Value |
|
Confidence level |
Oficial |
|
Impact |
Ejecucion remota de codigo |
|
Dificulty |
Principiante |
|
Required attacker level |
Acceso remoto sin cuenta a un servicio estandar |
System information
|
|
Property |
Value |
|
Affected manufacturer |
Comercial Software |
|
Affected software |
ZAPms versión 1.41 y anteriores |
Description
|
|
Vulnerabilidad de inyección SQL en ZAPms v1.41 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro pid al producto. |
Solution
|
|
Aún no hay solución al problema |
Standar resources
|
|
Property |
Value |
|
CVE |
CVE-2013-3050 |
|
BID |
|
Other resources
|
INTECO
http://cert.inteco.es/vulnDetail/Actualidad/Actualidad_Vulnerabilidades/detalle_vulnerabilidad/CVE-2013-3050 |