vendor:
WEBPack Management System
by:
Halil Dalabasmaz
9,8
CVSS
CRITICAL
SQL Injection & Unauthorized Access To Sensetive Information
89
CWE
Product Name: WEBPack Management System
Affected Version From: 1.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: CVE-2016-7456
CPE: o:exagate:webpack_management_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2016
Exagate WEBpack Management System Multiple Vulnerabilities
There is no any filtering or validation mechanisim on "login.php". "username" and "password" inputs are vulnerable to SQL Injection attacks. The software is capable of sending e-mail to system admins. But there is no any authorization mechanism to access e-mail logs. The e-mail logs can accesed by anyone.
Mitigation:
The vendor should implement proper authorization mechanism to access e-mail logs.