Release date:
Updated on: 2014-05-10
Affected Systems:
Collabtive 1.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67287
CVE (CAN) ID: CVE-2014-3246
Collabtive is an open source project management software.
The folder parameter of Collabtive 1.2 and other versions has the SQL injection vulnerability. Attackers can exploit this vulnerability to perform unauthorized database attacks.
<* Source: Deepak Rathore
Link: http://www.exploit-db.com/exploits/33249/
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://example.com/collabtive-12/manageajax.php? Action = fileview_list & amp; id = 2482 & amp; folder = 1 [SQL-injection]
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Collabtive
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://collabtive.o-dyn.de/downloadref.php
This article permanently updates the link address: