vendor:
Collabtive
by:
Anatolia Security
9
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Collabtive
Affected Version From: 0.65
Affected Version To: 0.7.1
Patch Exists: YES
Related CWE: N/A
CPE: a:collabtive:collabtive
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Collabtive SQL Injection Vulnerability
Collabtive has 'union' type SQL injection vulnerability. In 'managechat.php' when the value of parameter 'actions' equal to 'pull' application gets value of the cookie named like chatstart[USERTOID]. Application apply mysql_real_escape_string function to same variable but include it without quotes. So mysql_real_escape_string function can't provide any security in this case. Attacker can exploit this vulnerability for executing arbitrary sql codes.
Mitigation:
Upgrade to the latest version of Collabtive (0.7.1)