[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] InvGate Service Desk post-auth SQL injection as non-privileged user
- To: "fulldisclosure@xxxxxxxxxxxx" <fulldisclosure@xxxxxxxxxxxx>
- Subject: [FD] InvGate Service Desk post-auth SQL injection as non-privileged user
- From: Brandon Perry <bperry.volatile@xxxxxxxxx>
- Date: Tue, 8 Jul 2014 13:12:45 -0500
Hi,
https://gist.github.com/brandonprry/fc4d396ca7503d49a0f5
Detailed in the above gist is a slew of SQL injections available to an
authenticated but non-privileged user in the latest available version (from
their website) of InvGate.
--
http://volatile-minds.blogspot.com -- blog
http://www.volatileminds.net -- website
_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/