Bugtraq mailing list archives
[eVuln] vCounter - sourceworkshop SQL Injection Vulnerability
From: alex () evuln com
Date: 7 Apr 2006 16:33:52 -0000
New eVuln Advisory: vCounter - sourceworkshop SQL Injection Vulnerability http://evuln.com/vulns/108/summary.html --------------------Summary---------------- eVuln ID: EV0108 CVE: CVE-2006-1499 Software: vCounter Sowtware's Web Site: http://www.sourceworkshop.com/ Versions: 1.0 Critical Level: Harmless Type: SQL Injection Class: Remote Status: Unpatched. Developer(s) contacted. PoC/Exploit: Not Available Solution: Not Available Discovered by: Aliaksandr Hartsuyeu (eVuln.com) -----------------Description--------------- Vulnerable script: vCounter.php Variable $_SERVER[REQUEST_URI] is not properly sanitized before being used in 'INSERT' SQL query. This can be used to evaluate arbitrary SQL expression. Condition: magic_quotes_gpc = off --------------PoC/Exploit---------------------- Available at: http://evuln.com/vulns/108/exploit.html --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu (eVuln.com) Regards, Aliaksandr Hartsuyeu http://evuln.com - Penetration Testing Services .
Current thread:
- [eVuln] vCounter - sourceworkshop SQL Injection Vulnerability alex (Apr 09)