Overview
IPSwitch's WhatsUp Gold version 16.3, and possibly previous versions, is vulnerable to SQL injection and cross-site scripting attacks.
Description
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - CVE-2015-6004 The "Find Device" search field does not properly neutralize user input, allowing an unauthenticated (e.g., the guest account) attacker to perform SQL queries and commands by inserting ticks or percent characters.
These fields appear to be only accessible by privileged accounts (e.g., administrator accounts) and therefore are unlikely to be exploited in practice. According to the reporters, WhatsUp Gold version 16.3 is affected by these vulnerabilities. Other versions may also be affected. The CVSS score below is based on CVE-2015-6004. |
Impact
An unauthenticated remote attacker may perform SQL commands on the backend database. An administrator may be able to perform cross-site scripting attacks on other administrators and users. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Temporal | 5.9 | E:POC/RL:OF/RC:C |
Environmental | 4.4 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to an anonymous researcher working with Beyond Security's SSD program, Owen Shearing of 7Safe Ltd., and Rapid7 for independently reporting SQL injection issues to us. Thanks to the anonymous researcher and Rapid7 for also reporting cross-site scripting vulnerabilities.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2015-6004, CVE-2015-6005 |
Date Public: | 2015-12-16 |
Date First Published: | 2015-12-16 |
Date Last Updated: | 2015-12-27 21:23 UTC |
Document Revision: | 71 |