Secunia Security Advisory - A vulnerability has been reported in Fujitsu MyWeb products, which can be exploited by malicious people to conduct SQL injection attacks.
960742f7b4b952b182d0be2121e6090e665a44fe3eb34ad1a48df19c00a45c93
TITLE:
Fujitsu MyWeb Products SQL Injection Vulnerability
SECUNIA ADVISORY ID:
SA20178
VERIFY ADVISORY:
http://secunia.com/advisories/20178/
CRITICAL:
Moderately critical
IMPACT:
Manipulation of data
WHERE:
>From remote
SOFTWARE:
Fujitsu MyWeb Standard Edition
http://secunia.com/product/10069/
Fujitsu MyWeb School Edition
http://secunia.com/product/10073/
Fujitsu MyWeb Public Edition
http://secunia.com/product/10070/
Fujitsu MyWeb Portal Office
http://secunia.com/product/10068/
Fujitsu MyWeb Medical Edition 4.x
http://secunia.com/product/10071/
Fujitsu MyWeb Light Edition
http://secunia.com/product/10074/
Fujitsu MyWeb Citizen Edition 3.x
http://secunia.com/product/10072/
DESCRIPTION:
A vulnerability has been reported in Fujitsu MyWeb products, which
can be exploited by malicious people to conduct SQL injection
attacks.
Input passed to unspecified parameters isn't properly sanitised
before being used in a SQL query. This can be exploited to manipulate
SQL queries by injecting arbitrary SQL code.
The vulnerability has been reported in the following products:
* MyWeb Portal Office
* MyWeb Standard Edition
* MyWeb Public Edition
* MyWeb Medical Edition
* MyWeb Citizen Edition
* MyWeb School Edition
* MyWeb Light Edition
SOLUTION:
Contact the vendor for updated versions.
http://www.myweb-jp.com/resq/
PROVIDED AND/OR DISCOVERED BY:
Reported by vendor.
ORIGINAL ADVISORY:
http://software.fujitsu.com/jp/security/vulnerabilities/jvn-55425662.html
http://www.myweb-jp.com/support/tech/tech_common_013.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------