CVE-2012-3469
Description
Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the messages admin functionality in application/controllers/admin/messages.php, (2) application/libraries/api/MY_Checkin_Api_Object.php, (3) application/controllers/admin/messages/reporters.php, or (4) the location API in application/libraries/api/MY_Locations_Api_Object.php and application/models/location.php.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://github.com/ushahidi/Ushahidi_Web/commit/e0e2b66
Vendor advisory: secalert@redhat.com — https://github.com/ushahidi/Ushahidi_Web/commit/a11d43c
Vendor advisory: secalert@redhat.com — https://github.com/ushahidi/Ushahidi_Web/commit/6f6a919
Vendor advisory: secalert@redhat.com — https://github.com/ushahidi/Ushahidi_Web/commit/68d9916
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ushahidi | ushahidi_platform | {"endIncluding":"2.4.1"} | |
| ushahidi | ushahidi_platform | 1.0 | |
| ushahidi | ushahidi_platform | 1.2 | |
| ushahidi | ushahidi_platform | 2.0 | |
| ushahidi | ushahidi_platform | 2.1 | |
| ushahidi | ushahidi_platform | 2.2 | |
| ushahidi | ushahidi_platform | 2.2.1 | |
| ushahidi | ushahidi_platform | 2.3.1 | |
| ushahidi | ushahidi_platform | 2.3.2 | |
| ushahidi | ushahidi_platform | 2.4 | |
References
- http://openwall.com/lists/oss-security/2012/08/09/5
- https://github.com/ushahidi/Ushahidi_Web/commit/68d9916
- https://github.com/ushahidi/Ushahidi_Web/commit/6f6a919
- https://github.com/ushahidi/Ushahidi_Web/commit/a11d43c
- https://github.com/ushahidi/Ushahidi_Web/commit/e0e2b66
- http://openwall.com/lists/oss-security/2012/08/09/5
- https://github.com/ushahidi/Ushahidi_Web/commit/68d9916
- https://github.com/ushahidi/Ushahidi_Web/commit/6f6a919
- https://github.com/ushahidi/Ushahidi_Web/commit/a11d43c
- https://github.com/ushahidi/Ushahidi_Web/commit/e0e2b66
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.