Release date:
Updated on:
Affected Systems:
I-doit Pro 1.2.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65557
CVE (CAN) ID: CVE-2014-1597
I-doit Pro is an open-source IT documentation and CMDB.
I-doit Pro 1.2.4 and earlier Web applications have multiple SQL injection vulnerabilities, which allow attackers to perform unauthorized database operations.
<* Source: Stephen Rickauer
Link: http://seclists.org/fulldisclosure/2014/Feb/154
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com /? ObjID = [SQL Injection]
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
I-doit
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.i-doit.org/