Discussions
Read on for the latest updates including:
• Agenda Builder launch
• SuiteWorld On Air registration
• New NetSuite Prompt Studio Contest
• And more!
Check out this thread to learn more!
ScanAlert Vulnerability - Database Error Disclosure Vulnerability
NS,
Can you please advise if you received a warning for the following vulnerability?
Database Error Disclosure Vulnerability
Description
During our analysis of your web application, we were able to intentionally generate database specific errors. By causing a system to generate errors such as these, it is often possible to determine the database version and inject database command syntax that would allow us to extract data.
However, during our review of the system output, we were unable to identify the database version preventing us from exploiting this further. The danger exists in that a determined hacker might be able to determine the proper syntax and extract data or gain control of the system.