Cool Messenger Server and Cool Manager "username" Remote SQL Injection Vulnerability
Description
A vulnerability has been identified in Cool Messenger Server and Cool Manager, which may be exploited by attackers to execute arbitrary SQL commands. This flaw is due to an input validation error in the "Cool_CoolID.exe" utility when processing the "username" parameter before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks and gain unauthorized access to a vulnerable application.
Vulnerable Products
Vulnerable Software: Cool Messenger Server versions prior to 5.5 (5,65,12,13)Cool Manager versions prior to 5.0 (5,60,90,28)