This application requires Javascript for optimal performance.

TankLogger.ShowInfo.PHP.Livestock.Id.Parameter.SQL.Injection

Release Date

Dec 01, 2009

Severity

high

Impact

System Compromise: Remote attackers can execute arbitrary sql statements in vulnerable systems.

Description

This indicates an attack attempt to exploit the SQL injection vulnerability in TankLogger web application.

The vulnerability is a result of the application's failure to properly sanitize user input before using it in a SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server.

Affected Products

TankLogger TankLogger 2.4

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-0209

Reference/s

http://www.securityfocus.com/bid/16228 (BugTraq)

Reference: VID-17941