Vulnerabilities > CVE-2002-0539 - SQL Injection vulnerability in Demarc PureSecure Authentication Check

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
demarc-security
critical
exploit available

Summary

Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.

Vulnerable Configurations

Part Description Count
Application
Demarc_Security
2

Exploit-Db

descriptionDemarc PureSecure 1.0.5 Authentication Check SQL Injection Vulnerability. CVE-2002-0539. Remote exploits for multiple platform
idEDB-ID:21384
last seen2016-02-02
modified2002-04-15
published2002-04-15
reporterpokleyzz sakamaniaka
sourcehttps://www.exploit-db.com/download/21384/
titleDemarc PureSecure 1.0.5 - Authentication Check SQL Injection Vulnerability