GateSoft Docusafe "ECO.asp" SQL Injection

  Bookmark
 and Share

GateSoft Docusafe is an ASP-based Product Document Management (PDM) system. The application is exposed to an SQL injection issue because it fails to sufficiently sanitize user-supplied data to the "ECO_ID" parameter of the "ECO.asp"script before using it in an SQL query. GateSoft Docusafe version 4.1.0 is affected.

Ref: http://www.securityfocus.com/bid/45182

10.50.45 - CVE: Not Available
Platform: Web Application - SQL Injection