Release date:
Updated on:
Affected Systems:
Construtiva CIS Manager
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67442
CVE (CAN) ID: CVE-2014-3749
The CIS Manager platform is a tool for managing sites and enterprise portals.
CIS Manager does not correctly verify the validity of the 'email 'parameter value. An SQL injection vulnerability exists in the implementation. Attackers can exploit this vulnerability to perform unauthorized database operations.
<* Source: Edge
Link: http://www.exploit-db.com/exploits/32660/
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/autenticar/lembrarlogin.asp? Email = [SQL Injection]
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Construtiva
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.construtiva.com.br/
This article permanently updates the link address: