[Japanese] | |
JVNDB-2006-000631 | |
ACollab SQL injection vulnerability | |
Overview | |
ACollab is open source web-based groupware and is also available as an add-on for e-learning content management system ATutor. ACollab contains a SQL injection vulnerability. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 7.5 (High) [IPA Score]
| |
Affected Products | |
| |
ATRC | |
| |
Impact | |
A remote attacker could modify the database contents or steal data. An attacker could also bypass authentication and impersonate a user. | |
Solution | |
Development and maintenance of ACollab finished with version 1.2 as of July 6, 2006. However ATutor 1.5.3 includes the almost same functionality as ACollab. Users of ACollab are recommended to swith to ATutor 1.5.3. | |
Vendor Information | |
ATRC | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2006/07/06 |
Date First Published | 2008/05/21 |
Date Last Updated | 2008/05/21 |