INL Ulog-php Port.PHP SQL Injection Vulnerability
BID:11018
Info
INL Ulog-php Port.PHP SQL Injection Vulnerability
| Bugtraq ID: | 11018 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2004 12:00AM |
| Updated: | Aug 23 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
INL Ulog-php 0.8.1 INL Ulog-php 0.8 |
| Not Vulnerable: |
INL Ulog-php 0.8.2 |
Discussion
INL Ulog-php Port.PHP SQL Injection Vulnerability
It is reported that INL Ulog-php is susceptible to an SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Versions prior to 0.8.2 are reported to be affected.
It is reported that INL Ulog-php is susceptible to an SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in compromise of the application, disclosure or modification of data or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Versions prior to 0.8.2 are reported to be affected.
Exploit / POC
INL Ulog-php Port.PHP SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
INL Ulog-php Port.PHP SQL Injection Vulnerability
Solution:
The vendor has released an update to address this issue:
INL Ulog-php 0.8
INL Ulog-php 0.8.1
Solution:
The vendor has released an update to address this issue:
INL Ulog-php 0.8
-
INL ulog-php-0.8.2.tar.gz
http://www.inl.fr/download/ulog-php-0.8.2.tar.gz
INL Ulog-php 0.8.1
-
INL ulog-php-0.8.2.tar.gz
http://www.inl.fr/download/ulog-php-0.8.2.tar.gz