| Name | Chimera.Web.Portal.Linkcategory.Id.Parameter.SQL.Injection |
| Release Date | Nov 11, 2009 |
| Severity | Medium |
| Impact | Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems. |
| Description | This indicates an attack attempt to exploit an SQL-injection vulnerability in Chimera Web Portal System.
The vulnerability is a result of the application's failure to properly sanitize user input before using it in an SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server. |
| Affected Products | Chimera Web Portal version 0.2 |
| Recommended Actions | Upgrade the software to the latest versions. |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-0137
|
| Reference/s | http://www.securityfocus.com/bid/16113 (BugTraq)
|