OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: New vulnerability in Xerox Fiery Webtools

laurent.hermelinefi.com
Date: Thu Nov 12 2009 - 09:21:42 CST


There is no SQL Injection Vulnerability in WebTools as we are not using Database. MyDocs url ("/wt3/
summary.php?select=") is safe as "select" is just name of a variable and the name is nothing to do with select command in SQL.

Please provide details about the Fiery model and version so that we can close this report.