SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  HelpDesk PRO (WebSoft) Vendors:  WebSoft
HelpDesk PRO Input Validation Flaw Lets Remote Users Bypass Authentication Via SQL Command Injection
SecurityTracker Alert ID:  1010590
SecurityTracker URL:  http://securitytracker.com/id?1010590
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Jun 26 2004
Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Advisory:  Zone-H
Version(s): 2.0
Description:  D'Amato Luigi from Zone-h Security Labs reported a vulnerability in WebSoft's HelpDesk PRO. A remote user can inject SQL commands.

It is reported that the login page does not properly validate user-supplied input. A remote user can bypass the application's authentication mechanism to gain access to the application, the advisory said.

The original advisory is available at:

http://www.zone-h.org/en/advisories/read/id=4891/

Impact:  A remote user can inject SQL commands to gain access to the application.
Solution:  The vendor has reportedly issued a patch.
Vendor URL:  www.websoft.it/ (Links to External Site)
Cause:  Input validation error
Reported By:  D'Amato Luigi <admin@securitywireless.info>
Message History:   None.


 Source Message Contents

Date:  Sat, 26 Jun 2004 11:48:34 +0100
From:  D'Amato Luigi <admin@securitywireless.info>
Subject:  ZH2004-13SA (security advisory): Sql Injection in Help Desp Pro 2.0

 


26/06/2004

ZH2004-10SA (security advisory): Sql Injection in Help Desp Pro 2.0
Date of discovery : 1 Giugno 2004

Date of release  26 Giugno 2004

Nome: Help Desk Pro

Vulnerable Version: 2.0 non patchato

Vulnerability: Sql Injection

Autore: D'Amato Luigi from Zone-h Security Labs -
securitywireless@zone-h.it <mailto:securitywireless@zone-h.it> -
admin@securitywireless.info <mailto:admin@securitywireless.info>

Vendor: http://www.websoft.it/


Description

**********
Zone-H Security Team has discovered a flaw of securityin Help Desk Pro. This
vulnerability could allow malicious
attackers to bypass the authentication mechanish without having an account

Detail
********************************************
Due to an improper login validation in the login page it is possible to
bypass the authentication mechanism

Solution
**********
The vendor have been contact and have release a patch


---

D'Amato Luigi from Zone-h Security Labs -
securitywireless@zone-h.it <mailto:securitywireless@zone-h.it> -
admin@securitywireless.info <mailto:admin@securitywireless.info>
Admin Security Wireless
http://www.securitywireless.info

http://www.zone-h.org/en/advisories/read/id=4891/


 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC