vendor:
Thru Managed File Transfer Portal
by:
Dr. Erlijn van Genuchten, Danny Österreicher (SySS GmbH)
7,5
CVSS
HIGH
SQL Injection (CWE-89)
89
CWE
Product Name: Thru Managed File Transfer Portal
Affected Version From: 9.0.2
Affected Version To: 9.0.2
Patch Exists: YES
Related CWE: Not yet assigned
CPE: a:thru:thru_managed_file_transfer_portal
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
SQL Injection in Thru Managed File Transfer Portal
An SQL injection vulnerability was identified in one of the GET request. The SQL injection vulnerability was found in a GET request that causes contact data to be sorted. At least the attribute values of sortorder and letterrange are not correctly sanitized and therefore can be abused to inject arbitrary SQL statements.
Mitigation:
Update to the new software version.