Release date:
Updated on:
Affected Systems:
KnowledgeTree <= 3.7.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66988
CVE (CAN) ID: CVE-2014-2737
KnowledgeTree is a document management system.
KnowledgeTree 3.7.0.2 and earlier versions have the SQL blind injection vulnerability in implementation of/webservice/clienttools/services/mdownload. php. Unauthorized database attacks can be exploited without authentication. This vulnerability is located in the get_active_session function of the KTAPI_UserSession class. When querying an active Session, the query is not parameterized. The unverified "u" parameter is passed in the getFileName function. This vulnerability can be exploited by/webservice/clienttools/services/mdownload. php.
<* Source: Craig Arendt
Link: http://www.securityfocus.com/archive/1/531886
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
KnowledgeTree
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.knowledgetree.com