Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [eVuln] Skull-Splitter's PHP Downloadcounter for Wallpapers SQL Injection

  [eVuln] Skull-Splitter's PHP Guestbook XSS Vulnerability

  XSS in PHPKIT Version 1.6.03

  [SA19443] PHP Script Index "search" Cross-Site Scripting Vulnerability

From:Aliaksandr Hartsuyeu <alex_(at)_evuln.com>
Date:29.03.2006
Subject:[eVuln] Maian Support Authentication Bypass

New eVuln Advisory:
Maian Support Authentication Bypass
http://evuln.com/vulns/103/summary.html

--------------------Summary----------------
eVuln ID: EV0103
CVE: CVE-2006-1259
Software: Maian Support
Sowtware's Web Site: http://www.maianscriptworld.co.uk/
Versions: 1.0
Critical Level: Moderate
Type: SQL Injection
Class: Remote
Status: Unpatched. Developer(s) contacted.
PoC/Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)

-----------------Description---------------
Vulnerable script: admin/index.php

Parameters email, pass are not properly sanitized before being used in SQL query. This can be used to bypass authentication using SQL injection or make any SQL query by injecting arbitrary SQL code.

Condition: magic_quotes_gpc = off

--------------PoC/Exploit----------------------
Available at: http://evuln.com/vulns/103/exploit.html

--------------Solution---------------------
No Patch available.

--------------Credit-----------------------
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)


Regards,
Aliaksandr Hartsuyeu
http://evuln.com - Penetration Testing Services
.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru