vendor:
Family Connections
by:
Salvatore Fresta aka Drosophila
7.5
CVSS
HIGH
Multiple Blind SQL Injection, Multiple SNMP Injection
89, 200
CWE
Product Name: Family Connections
Affected Version From: 2.2.2003
Affected Version To: 2.2.2003
Patch Exists: NO
Related CWE:
CPE: a:family_connections:family_connections:2.2.3
Platforms Tested:
2010
Family Connections 2.2.3 Multiple Remote Vulnerabilities
The Family Connections version 2.2.3 is affected by multiple vulnerabilities, including multiple blind SQL injection and multiple SNMP injection. The blind SQL injection vulnerability exists in the numeric fields, which are not properly sanitized. The SNMP injection vulnerability allows injecting arbitrary SNMP headers by improperly sanitizing the parameters passed to the mail() PHP function.
Mitigation:
The vendor should properly sanitize the input fields to prevent blind SQL injection and SNMP injection vulnerabilities.