vendor:
Supportworks ITSM
by:
Joseph Sheridan of ReactionIS
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Supportworks ITSM
Affected Version From: 1.0.0
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: CVE-2013-2594
CPE: a:hornbill:supportworks_itsm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
SQL Injection Vulnerability in ITSM component of Hornbill Supportworks Application
There is a SQL injection vulnerability in the ITSM component of the Supportworks Application. The vulnerable file is calldiary.php found in the /reports folder of the webroot. The following URL demonstrates the issue: http://vulnhost.com/reports/calldiary.php?callref=VULN This attack can be used to take full control of the host by writing a php webshell document (using mysql 'into outfile') to the webroot.
Mitigation:
Upgrade to the latest available ITSM version - contact Vendor for more details.