J-Security Center

Title: VideoDB Unspecified SQL Injection Vulnerability

Severity: HIGH

Description:

VideoDB is a database front-end to manage your personal video collection. It's mainly designed for video files but you can also put your DVDs and VHS tapes in it, it is written in PHP utilizing a MySQL database.

VideoDB is reportedly affected by an unspecified SQL injection vulnerability. This is due to the application failing to properly sanitize user-supplied input before being used in an SQL query.

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

The vendor has not released very many details about the vulnerability except VideoDB versions 2.0.0 and prior are affected. They have also released VideoDB 2.0.2 that reportedly addresses the issue.

Affected Products:

  • VideoDB VideoDB 2.0.0 .0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.