
CIA RESEARCH
Alerts
[CIA-1034-Alert] MySQL Eventum ‘class.auth.php’ Multiple Vulnerabilities
Summary:
MySQL Eventum v. 1.5.5 and previous are affected by multiple SQL Injection
and Cross-Site Scripting vulnerabilities.
Technical Details:
Various scripts within MySQL Eventum do not properly validate
user-supplied input, allowing a remote attacker to conduct Cross-Site Scripting attacks.
Cross-Site Scripting vulnerabilities arise when a web application fails to filter user input,
allowing an attacker to craft malicious input that when supplied to the application result
in the application behaving as a relay, passing the malicious data on to the legitimate
users of the target application. Several scripts within Eventum have been reported to be
vulnerable.
1. /reports/custom_fields.php
2. /reports/custom_fields_graph.php
3. /manage/releases.php
4. /view.php
5. /list.php
In addition, other scripts allow SQL Injection attacks, which
grant an attacker the ability to execute commands on the underlying database. This can
result in an attacker obtaining access to confidential or sensitive information stored within
the MySQL database.
Solution:
Upgrade to 1.6.0 available at the link below:
http://dev.mysql.com/downloads/other/eventum/
CVE Reference:
GENERIC-MAP-NOMATCH
SecurityTracker Number(s):
1014603
Vendor URL:
http://www.mysql.com/
About the Cenzic CIA Team:
Cenzic Intelligent Analysis (CIA) is Cenzic’s
research arm that focuses on continuous research for application vulnerabilities.
Industry Research, Vulnerability assessment, penetration testing, and security
testing — that’s what Cenzic Intelligent Analysis Research is all about.
Cenzic has dedicated experts whose sole job is to perform ongoing research to
find not only common vulnerabilities but also vulnerabilities found in customer
applications and make them available to our customers and to the community at large.
About Cenzic:
Cenzic provides Hailstorm® the revolutionary enterprise
software suite for automated application security assessment and compliance that
allows corporations and government organizations to dramatically improve the
security of commercial and custom applications. Hailstorm enables security experts,
QA professionals, and developers to work together to assess, analyze, and remediate
applications for security vulnerabilities, and verify compliance with security policies.
Benefits include reduced security risk and liability, lower development and testing
costs, and faster time-to-market. Cenzic’s customers are currently in the financial
services and e-marketplaces sectors. For more information visit www.cenzic.com or call 1-866-4-CENZIC

|