
UNSOLVED
K2
kevins7189-2
2 Intern
•
9 Posts
0
2494
January 12th, 2022 09:00
OMSA 10.1 Vulernable to CGI Generic SQL Injection?
Our Tenible Nessus scanner is saying that OMSA 10.1 is Vulnerable to
CGI Generic SQL
Injection (blind,
time based)
Severity HIGH
Using the GET HTTP method, Nessus found that :
+ The following resources may be vulnerable to blind SQL injection (time based) :
+ The 'searchQuery' parameter of the /help/omahip/en/search.html CGI :
/help/omahip/en/search.html?searchQuery='%20AND%20SLEEP(21)='
-------- output --------
------------------------
Synopsis: A CGI application hosted on the remote web server is potentially prone to SQL injection attack.
Description: By sending specially crafted parameters to one or more CGI scripts hosted on the remote web server, Nessus was able to get a slower
response, which suggests that it may have been able to modify the behavior of the application and directly access the underlying database.
An attacker may be able to exploit this issue to bypass authentication, read confidential data, modify the remote database, or even take control of the
remote operating system.
Note that this script is experimental and may be prone to false positives
Solution: Modify the affected CGI scripts so that they properly escape arguments.
See Also: http://www.securiteam.com/securityreviews/5DP0N1P76E.html
http://www.nessus.org/u?ed792cf5
http://projects.webappsec.org/w/page/13246963/SQL%20Injection
Risk Factor: High
CVSS V3 Base Score:
Responses (0)
Solutions (0)
