Published:2011/05/19 Last Updated:2011/05/20
JVN#77697803
iVIEW Suite vulnerable to SQL injection
Overview
iVIEW Suite from RADVISION contains a SQL injection vulnerability.
Products Affected
- iVIEW Suite prior to v7.5
Description
iVIEW Suite provided by RADVISION is a software to manage video conference systems in SCOPIA. iVIEW Suite contains a SQL injection vulnerability.
Impact
A remote attacker may view or alter the information on the system.
Solution
Update the Software
Update to the latest version according to the information provided by the distributor.
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2011.05.19
Measures | Conditions | Severity |
---|---|---|
Access Required | can be attacked over the Internet using packets |
|
Authentication | anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls) |
|
Credit
Hirofumi Oka of NRI SecureTechnologies,Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2011-1328 |
JVN iPedia |
JVNDB-2011-000030 |
Update History
- 2011/05/19
- Published in English
- 2011/05/20
- Information under the sections "References" were modified.