vendor:
Collabtive
by:
Anonymous
6,5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Collabtive
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: 2013-6872
CPE: a:collabtive:collabtive
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013
Collabtive Sql Injection
Double query type of SQL Injection vulnerability has been detected in Collabtive web applivation. Application failed to sanitize user supplied input in parameter 'id' of page managetimetracker.php. User must be authenticated to exploit this vulnerability.
Mitigation:
Input validation and sanitization should be done to prevent SQL Injection attacks.