Release date:
Updated on:
Affected Systems:
Authenex Authenex ASAS Server 3.1.0.3
Authenex Authenex ASAS Server 3.1.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49722
Authenex ASAS Server is an authentication and mobile data security system.
The username parameter in Authenex ASAS Server has the SQL injection vulnerability. Remote attackers can exploit this vulnerability to control applications and access or modify data.
Input sent to akeyActivationLogin. do using the username parameter is not properly filtered before being used for SQL queries. You can operate SQL queries by injecting any SQL code. The "End User Self Service" module must be run successfully.
<* Source: Jose Carlos de Arriba
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/akeyActivationLogin.do
Post data: rgstcode = 1111111111111111 & amp; username = A'; waitfor delay '0: 0: 30 '--
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Authenex
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.authenex.com/index.php? _ M = downloads & _ a = viewdownload & downloaditemid = 126