ID

VAR-201303-0457


TITLE

Polycom HDX Series SQL Injection Vulnerability

Trust: 0.9

sources: BID: 58526 // CNNVD: CNNVD-201303-339

DESCRIPTION

Polycom HDX Series devices are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an authenticated attacker to compromise the affected device, access or modify data, or exploit latent vulnerabilities in the underlying database.

Trust: 0.3

sources: BID: 58526

AFFECTED PRODUCTS

vendor:polycommodel:hdxscope:eqversion:90000

Trust: 0.3

vendor:polycommodel:hdxscope:eqversion:80000

Trust: 0.3

vendor:polycommodel:hdxscope:eqversion:70000

Trust: 0.3

vendor:polycommodel:hdxscope:eqversion:60000

Trust: 0.3

vendor:polycommodel:hdxscope:eqversion:40000

Trust: 0.3

vendor:polycommodel:hdxscope:neversion:90003.1.12

Trust: 0.3

vendor:polycommodel:hdxscope:neversion:80003.1.12

Trust: 0.3

vendor:polycommodel:hdxscope:neversion:70003.1.12

Trust: 0.3

vendor:polycommodel:hdxscope:neversion:60003.1.12

Trust: 0.3

vendor:polycommodel:hdxscope:neversion:40003.1.12

Trust: 0.3

sources: BID: 58526

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201303-339

TYPE

SQL injection

Trust: 0.6

sources: CNNVD: CNNVD-201303-339

EXTERNAL IDS

db:BIDid:58526

Trust: 0.9

db:CNNVDid:CNNVD-201303-339

Trust: 0.6

sources: BID: 58526 // CNNVD: CNNVD-201303-339

REFERENCES

url:http://www.securityfocus.com/bid/58526

Trust: 0.6

url:http://seclists.org/bugtraq/2013/mar/98

Trust: 0.3

url:http://www.polycom.com/

Trust: 0.3

sources: BID: 58526 // CNNVD: CNNVD-201303-339

CREDITS

Moritz Jodeit of n.runs AG

Trust: 0.9

sources: BID: 58526 // CNNVD: CNNVD-201303-339

SOURCES

db:BIDid:58526
db:CNNVDid:CNNVD-201303-339

LAST UPDATE DATE

2022-05-17T01:43:25.548000+00:00


SOURCES UPDATE DATE

db:BIDid:58526date:2013-03-15T00:00:00
db:CNNVDid:CNNVD-201303-339date:2013-03-19T00:00:00

SOURCES RELEASE DATE

db:BIDid:58526date:2013-03-15T00:00:00
db:CNNVDid:CNNVD-201303-339date:2013-03-18T00:00:00