92757vdb entry
http://osvdb.org/92757 CVE-2013-2594
Hornbill Supportworks ITSM 1.0.0 - SQL Injection
Record summary
CVE-2013-2594 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHornbill Supportworks ITSM 1.0.0 - SQL InjectionExploitDB exploitby Joseph SheridanNot analyzed1 file
References
8packetstormsecurity.com
http://packetstormsecurity.com/files/121402/Hornbill-Supportworks-ITSM-1.0.0-SQL-Injection.html 20130424 hornbill supportworks SQL injectionmailing list
http://seclists.org/fulldisclosure/2013/Apr/232 25002exploit
http://www.exploit-db.com/exploits/25002 reactionpenetrationtesting.co.uk
http://www.reactionpenetrationtesting.co.uk/hornbill-supportworks-sql-injection.html 59439vdb entry
http://www.securityfocus.com/bid/59439 hornbill-itsm-calldiary-sql-injection(83767)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/83767 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-2594