vendor:
Portalmanager
by:
SecurityFocus
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Portalmanager
Affected Version From: 4.3
Affected Version To: 4.3
Patch Exists: NO
Related CWE: N/A
CPE: //a:powerslave:powerslave_portalmanager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Powerslave Portalmanager Information Disclosure Vulnerability
It has been reported that Powerslave Portalmanager is prone to an information disclosure issue that may allow remote attackers to gain access to sensitive information about the underlying database structure. The problem is reported to exist in the sql_id parameter. An attacker may insert malformed SQL queries in sql_id, resulting in the software generating an error message and disclosing sensitive database information. Although unconfirmed attackers may also be able to execute arbitrary SQL commands under certain circumstances.
Mitigation:
Ensure that all user input is properly validated and filtered before being used in SQL queries.