This application requires Javascript for optimal performance.

Cybozu.Garoon.Workflow.SQL.Injection

Release Date

Oct 15, 2009

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an SQL injection vulnerability in Cybozu Garoon.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted URL. It allows a remote attacker to execute arbitrary SQL commands.

Affected Products

Cybozu Garoon 2.1.0 and previous versions

Recommended Actions

Upgrade to Cybozu Garoon version 2.1.1:

http://garoon.cybozu.co.jp/download/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4444

Reference/s

http://www.frsirt.com/english/advisories/2006/3399 (FrSIRT)
http://www.securityfocus.com/bid/19731 (BugTraq)

Reference: VID-17761