Mambo Open Source Mambo.PHP User Name SQL Injection Vulnerability
BID:14115
Info
Mambo Open Source Mambo.PHP User Name SQL Injection Vulnerability
| Bugtraq ID: | 14115 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2004 12:00AM |
| Updated: | Apr 02 2004 12:00AM |
| Credit: | The original discoverer of this vulnerability is unknown. |
| Vulnerable: |
Mambo Mambo Open Source 4.5.1 (1.0.9) Mambo Mambo Open Source 4.5.1 Beta 2 Mambo Mambo Open Source 4.5.1 Beta |
| Not Vulnerable: | |
Discussion
Mambo Open Source Mambo.PHP User Name SQL Injection Vulnerability
Mambo is prone to an SQL injection vulnerability. As a result, the attacker may modify the structure and logic of an SQL query that is made by the application.
Other attacks may be possible depending on the capabilities of the underlying database and the nature of the affected query.
Mambo is prone to an SQL injection vulnerability. As a result, the attacker may modify the structure and logic of an SQL query that is made by the application.
Other attacks may be possible depending on the capabilities of the underlying database and the nature of the affected query.
Exploit / POC
Mambo Open Source Mambo.PHP User Name SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Mambo Open Source Mambo.PHP User Name SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mambo Open Source Mambo.PHP User Name SQL Injection Vulnerability
References:
References:
- Mambo Open Source Homepage (Mambo)