Overview
Hummingbird CyberDOCS contains an SQL injection vulnerability that could allow a remote attacker to execute SQL commands.
Description
Hummingbird CyberDOCS (Hummingbird DM) is a web-based enterprise document management solution that runs on Windows NT/2000 using SQL database technology. The login page (loginact.asp on IIS) does not properly filter user input, allowing a remote attacker to supply SQL commands that may be executed by the underlying database. |
Impact
Depending on the configuration of the database system, an unauthenticated, remote attacker may be able to execute operating system commands, modify databases, or determine system configuration information. |
Solution
Upgrade This vulnerability does not exist in CyberDOCS 3.9 or later. Hummingbird recommends that customers upgrade to the most recent version of CyberDOCS. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was discovered and reported by ProCheckUp.
This document was written by Art Manion.
Other Information
CVE IDs: | None |
Severity Metric: | 3.90 |
Date Public: | 2003-10-06 |
Date First Published: | 2003-10-09 |
Date Last Updated: | 2003-10-09 16:24 UTC |
Document Revision: | 23 |