source: http://www.securityfocus.com/bid/44608/info Online Work Order Suite is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Online Work Order Suite 2.10 is vulnerable; other versions may also be affected. The following example data is available: ' or 1=1 or ''=''
Related ExploitsTrying to match CVEs (1): CVE-2010-4186
Trying to match OSVDBs (1): 68972
Other Possible E-DB Search Terms: Online Work Order Suite
|2009-08-10||Online Work Order Suite Lite Edition - Multiple Cross-Site Scripting Vulnerabilities||Moudi|
|2010-11-02||Online Work Order System (OWOS) Professional Edition - Authentication Bypass||L0rd CrusAd3r|