CVE-2011-4970

LCG Disk Pool Manager < 1.8.6 - SQL Injection via Multiple Function Parameters

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in LCG Disk Pool Manager (DPM) before 1.8.6, as used in EGI UDM, allow remote attackers to execute arbitrary SQL commands via the (1) r_token variable in the dpm_get_pending_req_by_token, (2) dpm_get_cpr_by_fullid, (3) dpm_get_cpr_by_surl, (4) dpm_get_cpr_by_surls, (5) dpm_get_gfr_by_fullid, (6) dpm_get_gfr_by_surl, (7) dpm_get_pfr_by_fullid, (8) dpm_get_pfr_by_surl, (9) dpm_get_req_by_token, (10) dpm_insert_cpr_entry, (11) dpm_insert_gfr_entry, (12) dpm_insert_pending_entry, (13) dpm_insert_pfr_entry, (14) dpm_insert_xferreq_entry, (15) dpm_list_cpr_entry, (16) dpm_list_gfr_entry, or (17) dpm_list_pfr_entry function; the (18) surl variable in the dpm_get_cpr_by_surl function; the (19) to_surl variable in the dpm_get_cpr_by_surls function; the (20) u_token variable in the dpm_get_pending_reqs_by_u_desc, (21) dpm_get_reqs_by_u_desc, (22) dpm_get_spcmd_by_u_desc, (23) dpm_insert_pending_entry, (24) dpm_insert_spcmd_entry, or (25) dpm_insert_xferreq_entry function; the (26) s_token variable in the dpm_get_spcmd_by_token, (27) dpm_insert_cpr_entry, (28) dpm_insert_gfr_entry, (29) dpm_insert_pfr_entry, (30) dpm_insert_spcmd_entry, (31) dpm_update_cpr_entry, (32) dpm_update_gfr_entry, or (33) dpm_update_pfr_entry function; or remote administrators to execute arbitrary SQL commands via the (34) poolname variable in the dpm_get_pool_entry, (35) dpm_insert_fs_entry, (36) dpm_insert_pool_entry, (37) dpm_insert_spcmd_entry, (38) dpm_list_fs_entry, or (39) dpm_update_spcmd_entry function.

References (6)

Core 6
Core References
Various Sources x_refsource_misc
http://site.pi3.com.pl/adv/disk_pool_manager_1.txt
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/03/12/1
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/03/10/1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/52487
Patch, Vendor Advisory x_refsource_confirm
https://wiki.egi.eu/wiki/SVG:Advisory-SVG-2012-2683
Exploit x_refsource_misc
http://blog.pi3.com.pl/?p=402

Scores

EPSS 0.0154
EPSS Percentile 72.4%

Details

CWE
CWE-89
Status published
Products (4)
disk_pool_manager_project/disk_pool_manager 1.8.2
disk_pool_manager_project/disk_pool_manager 1.8.3
disk_pool_manager_project/disk_pool_manager 1.8.5
disk_pool_manager_project/disk_pool_manager < 1.8.1
Published May 13, 2014
Tracked Since Feb 18, 2026