Published:2010/04/02  Last Updated:2010/04/02

JVN#60969543
HL-SiteManager vulnerable to SQL injection

Overview

HL-SiteManager from Heartlogic contains a SQL injection vulnerability.

Products Affected

  • HL-SiteManager

Description

HL-SiteManager from Heartlogic is a contents management system (CMS) software. HL-SiteManager contains a SQL injection vulnerability.

Impact

A remote attacker may view or modify information stored by the product.

Solution

Do not use HL-SiteManager
As patches will not be provided, users are recommended to discontinue use of HL-SiteManager and switch to a different product that provides equivalent functionality.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Analyzed on 2010.04.02

Measures Conditions Severity
Access Required Routed - can be attacked over the Internet using packets
  • High
Authentication None - anonymous or no authentication (IP addresses do not count)
  • High
User Interaction Required None - the vulnerability can be exploited without an honest user taking any action
  • High
Exploit Complexity Low-Medium - some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls)
  • Medium-High

Description of each analysis measures

Credit

Yuji Tounai of bogus.jp reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2010-1331
JVN iPedia JVNDB-2010-000010

Update History