Overview
Hummingbird CyberDOCS contains an SQL injection vulnerability that could allow a remote attacker to execute SQL commands.
Description
| Hummingbird CyberDOCS (Hummingbird DM) is a web-based enterprise document management solution that runs on Windows NT/2000 using SQL database technology. The login page (loginact.asp on IIS) does not properly filter user input, allowing a remote attacker to supply SQL commands that may be executed by the underlying database. | 
Impact
| Depending on the configuration of the database system, an unauthenticated, remote attacker may be able to execute operating system commands, modify databases, or determine system configuration information. | 
Solution
| Upgrade This vulnerability does not exist in CyberDOCS 3.9 or later. Hummingbird recommends that customers upgrade to the most recent version of CyberDOCS. | 
| 
 | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was discovered and reported by ProCheckUp.
This document was written by Art Manion.
Other Information
| CVE IDs: | None | 
| Severity Metric: | 3.90 | 
| Date Public: | 2003-10-06 | 
| Date First Published: | 2003-10-09 | 
| Date Last Updated: | 2003-10-09 16:24 UTC | 
| Document Revision: | 23 |