oss-sec mailing list archives
CVE-2013-4137: StatusNet v1.1.0: SQL injection
From: Joshua Wise <joshua () joshuawise com>
Date: Thu, 18 Jul 2013 00:14:47 -0700
This is an advisory for StatusNet v1.0.0 through v1.1.0. Multiple user-facing functions do not sanitize API input before interpolating it into database query strings. This can result of exfiltration of database data, and depending on MySQL server (mis)configuration, can also result in file I/O to the database server disk. StatusNet versions 1.1.1 and 1.0.2 have been released to correct these issues. Patching to these versions as soon as possible is advised. For more information, visit: http://status.net/2013/07/16/security-alert-sql-injection-attack-for-statusnet-1-0-x-and-1-1-x Advisory title: Multiple SQL injection vulnerabilities Product: StatusNet Discovered by: Elly Fong-Jones Joshua Wise (NVIDIA Corporation) Known vulnerable versions: 1.0.0 - 1.1.0 Tested: 1.1.0, 2013-07-16 Fixed in version: 1.1.1 Vulnerability type: CWE-89 (SQL Injection) CVE IDs: CVE-2013-4137 My thanks to the Evan Prodromou for his help in quickly responding to these issues and releasing a new version. joshua
Current thread:
- CVE-2013-4137: StatusNet v1.1.0: SQL injection Joshua Wise (Jul 18)