Openfire (ARCHIVED)

CallLogDAO in SIP Plugin enables SQL Injection

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Major Major
  • Resolution: Fixed
  • Affects Version/s: None
  • Fix Version/s: 3.6.1
  • Component/s: Plugins
  • Acceptance Test - Add?:
    No
  • Description:

    CallLogDAO in SIP Plugin is using prepared Statements.
    But still inserting SQL Query values in the initialization String.

    The values MUST be inserted in the prepared Statement via PreparedStatement Instance to prevent SQL Injection.

  • Environment:

    All

Issue Links

Activity

Hide
Guus der Kinderen added a comment - 11/10/08 02:17 PM

This should fix problem #2 as described in http://www.andreas-kurtz.de/advisories/AKADV2008-001-v1.0.txt

Show
Guus der Kinderen added a comment - 11/10/08 02:17 PM This should fix problem #2 as described in http://www.andreas-kurtz.de/advisories/AKADV2008-001-v1.0.txt
Guus der Kinderen made changes - 11/12/08 09:40 AM
Field Original Value New Value
Link This issue is related to JM-1489 [ JM-1489 ]
Guus der Kinderen made changes - 11/12/08 09:41 AM
Link This issue is related to JM-629 [ JM-629 ]
Hide
Guus der Kinderen added a comment - 11/12/08 09:41 AM

I've linked the other JIRA issues that relate to the same security advisory to this JIRA issue.

Show
Guus der Kinderen added a comment - 11/12/08 09:41 AM I've linked the other JIRA issues that relate to the same security advisory to this JIRA issue.
Gaston Dombiak made changes - 11/14/08 08:35 AM
Resolution Fixed [ 1 ]
Status Open [ 1 ] Closed [ 6 ]

People

Dates

  • Created:
    11/10/08 02:00 PM
    Updated:
    11/14/08 08:35 AM
    Resolved:
    11/14/08 08:35 AM

Time Tracking

Estimated:
4h
Original Estimate - 4 hours
Remaining:
4h
Remaining Estimate - 4 hours
Logged:
Not Specified
Time Spent - Not Specified