Description
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID parameter to the default URI.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Stephan Rickauer · textwebappsphp
https://www.exploit-db.com/exploits/39096
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91269
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56931
Various Sources x_refsource_confirm
http://www.i-doit.com/en/company/news/single-news/?tx_ttnews%5Btt_news%5D=141
Exploit x_refsource_misc
http://www.csnc.ch/misc/files/advisories/CVE-2014-1597_i-doit_SQL_Injection.txt
Exploit mailing-list
x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2014-02/0154.html
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65557
Scores
EPSS
0.0058
EPSS Percentile
69.1%
Details
CWE
CWE-89
Status
published
Products (9)
i-doit/i-doit
i-doit/i-doit
1.0
i-doit/i-doit
1.0.2
i-doit/i-doit
1.1.1
i-doit/i-doit
1.1.2
i-doit/i-doit
1.2.1
i-doit/i-doit
1.2.2
i-doit/i-doit
1.2.3
i-doit/i-doit
< 1.2.4
Published
Feb 27, 2014
Tracked Since
Feb 18, 2026