[Japanese]

JVNDB-2012-000053

Segue vulnerable to SQL injection

Overview

Segue contains a SQL injection vulnerability.

Segue is a content management system. Segue contains a SQL injection vulnerability.

Daiki Fukumori of Cyber Defense Institute, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 7.5 (High) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial

Affected Products


Segue Project
  • Segue

Impact

A remote, unauthenticated attacker may bypass authentication and login as an administrator.
Solution

[Do not use Segue]
Segue services will no longer be available after August 31, 2012.

Refer to the information provided by the developer for data migration.
Vendor Information

Segue Project
CWE (What is CWE?)

  1. SQL Injection(CWE-89) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2012-1255
References

  1. JVN : JVN#97995841
  2. National Vulnerability Database (NVD) : CVE-2012-1255
Revision History

[2012/06/01]
  Web page was published