vendor:
ROC Fraud Management System
by:
Anastasios Monachos
7,5
CVSS
HIGH
Blind-Time Based SQL Injection
89
CWE
Product Name: ROC Fraud Management System
Affected Version From: 7.4
Affected Version To: 7.4
Patch Exists: NO
Related CWE: CVE-2014-8728
CPE: a:subex:roc_fraud_management_system:7.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Subex ROC Fraud Management System v7.4 – Unauthenticated Blind-Time Based SQL Injection
A parameter at the login page of Subex ROC Fraud Management platform is vulnerable to blind-time based SQL injection. An unauthenticated malicious visitor is able to enumerate various information from the backend database including those of usernames and password hashes (select ranger_user_name,hashed_password from ROCDB.PASSWORDS where rownum<2). The hashes can further be cracked and be uesd to gain access to the application.
Mitigation:
Upgrade to the latest version of Subex ROC FMS.