Vulnerability Note VU#777007
Ipswitch WhatsUp Gold 15.02 contains SQL injection and XSS vulnerabilities
Overview
Ipswitch WhatsUp Gold 15.02 has been reported to contain blind SQL injection and cross-site scripting vulnerabilities.
Description
Ipswitch WhatsUp Gold 15.02 has been reported to contain blind SQL injection and cross-site scripting vulnerabilities. CWE-79 - CVE-2012-2601 - Blind SQL Injection |
Impact
An attacker may be able to execute arbitrary SQL commands and script. |
Solution
Apply an Update WhatsUp Gold 15.03 has been released to address these vulnerabilities. |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Ipswitch, Inc | Affected | 25 Jun 2012 | 04 Sep 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 8.7 | AV:N/AC:L/Au:S/C:C/I:C/A:P |
| Temporal | 6.8 | E:POC/RL:OF/RC:C |
| Environmental | 6.8 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://docs.ipswitch.com/NM/79_WhatsUp%20Gold%20v15/01_Release%20Notes/index.htm
- http://www.exploit-db.com/exploits/20035/
- http://cwe.mitre.org/data/definitions/79.html
- http://cwe.mitre.org/data/definitions/89.html
Credit
Thanks to Devon Kearns of Offensive Security for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2012-2601 CVE-2012-2589
- Date Public: 22 Jul 2012
- Date First Published: 04 Sep 2012
- Date Last Updated: 04 Sep 2012
- Document Revision: 16
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.