OSVDB ID: 23479

Title: VPMi Enterprise Service_Requests.asp UpdateID0 Parameter SQL Injection

Info

Disclosure

Feb 24, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

VPMi Enterprise has been reported to contain an SQL injection issue in the Service_Requests.asp script. Subsequent testing has indicated that while an error exception is thrown on some crafted input, the script will provide the error and sometimes a partial path but will not allow SQL query manipulation. The path disclosed is the same information provided in the URL, so it is not a privileged information disclosure.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
OSVDB: Web Related, Myth / Fake

Solution

The vulnerability reported is incorrect. No solution required.

Products

Virtual Communication Services L.L.C

VPMi Enterprise

3.3

References

Credit

  • RedTeam Pentesting - RedTeam Pentesting


Direct URL: http://osvdb.org/23479