eDirectory
cpe:2.3:a:microfocus:edirectory:*:*:*:*:*:*:*, +2 more
- <= 1.0
A SQL injection vulnerability has been identified in eDirectory, affecting all versions. This vulnerability allows unauthenticated attackers to bypass administrator authentication and access sensitive files. The issue arises from improper neutralization of SQL code in parameters, which can be exploited to inject malicious SQL and manipulate database queries.
Exploitation of this vulnerability allows for authentication bypass, granting attackers administrative access, and the ability to disclose sensitive files from the server.
The vulnerability can be reproduced by injecting SQL code into the 'key' parameter of the login endpoint. This can be done using a union-based SQL injection to authenticate as an administrator. Once authenticated, the file disclosure vulnerability can be exploited by accessing 'language_file.php' and specifying a path to a PHP file on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.