Vulnerability Note VU#406596
Askiaweb survey application contains multiple vulnerabilities
Overview
The Askiaweb survey application contains multiple vulnerabilities.
Description
The Askiaweb survey application contains multiple vulnerabilities. CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - CVE-2013-0123 |
Impact
An attacker with access to the Askiaweb survey application web interface can conduct a cross-site scripting or sql injection attack, which could be used to result in information leakage, privilege escalation, and/or denial of service. |
Solution
We are currently unaware of a practical solution to this problem. |
Restrict access |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Askia | Affected | - | 11 Mar 2013 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 8.5 | AV:N/AC:L/Au:S/C:C/I:C/A:N |
| Temporal | 6.5 | E:U/RL:U/RC:UC |
| Environmental | 1.7 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://cwe.mitre.org/data/definitions/79.html
- http://cwe.mitre.org/data/definitions/89.html
- http://www.askia.com/askiaweb
Credit
Thank you to the reporter that wishes to remain anonymous.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2013-0123 CVE-2013-0124
- Date Public: 18 Mar 2013
- Date First Published: 20 Mar 2013
- Date Last Updated: 20 Mar 2013
- Document Revision: 10
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.