HTTP: Mambo com_docman Component SQL Injection

This signature detects attempts to exploit a known vulnerability in the Mambo com_docman component. It is due to insufficient validation of user-supplied input. An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.

Extended Description

The 'com_docman' component for Mambo is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. 'com_docman' 1.3 is vulnerable.

Affected Products

Docman com_docman

References

BugTraq: 47857

Short Name
HTTP:SQL:INJ:MAMBO-COM-DOCMAN
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Component Injection Mambo SQL bid:47857 com_docman
Release Date
05/18/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Docman

Found a potential security threat?