[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

RJ-iTop Network Vulnerability Scanner System Multiple SQL Injection Vuln

Author
wsn1983
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11814
Category
web applications
Date add
14-04-2010
Platform
jsp
===================================================================================
RJ-iTop Network Vulnerability Scanner System Multiple SQL Injection Vulnerabilities 
===================================================================================

RJ-iTop Network Vulnerability Scanner System Multiple SQL Injection Vulnerabilities
 
 
 
Vulnerable: v3.0.7.x
 
Vendor:  www.rj-itop.com<http://www.rj-itop.com>
 
Category: Input Validation Error
 
Impact:   SQL injection
 
 
 
Details:
 
=========
 
Multiple SQL Injection Vulnerabilities has been found in DRJ-iTop Network Vulnerability Scanner System&#65292; which can be exploited by malicious users to conduct SQL injection and script insertion attacks.
 
Authentication is required to exploit these vulnerabilities.
 
 
 
POC:
 
=========
 
https://8.8.8.8/roleManager.jsp?type=query&id= [SQL Injection]
 
 
 
 
 
Timeline:
 
========
 
2009.10.19   Report to vendor (but vender did not respond)
 
2009.11.15   Report to vendor second times
 
2009.11.19   Report to CNNVD
 
2010.04.13   Public



#  0day.today [2024-09-28]  #