Geeklog User Comment Retrieval SQL Injection Vulnerability
BID:14143
Info
Geeklog User Comment Retrieval SQL Injection Vulnerability
| Bugtraq ID: | 14143 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2005 12:00AM |
| Updated: | Jul 05 2005 12:00AM |
| Credit: | Discovery is credited to Stefan Esser <[email protected]> with Hardened-PHP Project. |
| Vulnerable: |
Geeklog Geeklog 1.3.11 rc1 Geeklog Geeklog 1.3.11 Geeklog Geeklog 1.3.10 Geeklog Geeklog 1.3.9 sr3 Geeklog Geeklog 1.3.9 sr2 Geeklog Geeklog 1.3.9 sr1 Geeklog Geeklog 1.3.9 Geeklog Geeklog 1.3.8 rc2 Geeklog Geeklog 1.3.8 rc1 Geeklog Geeklog 1.3.8 -1sr2 Geeklog Geeklog 1.3.8 -1sr1 Geeklog Geeklog 1.3.8 -1 Geeklog Geeklog 1.3.8 Geeklog Geeklog 1.3.7 sr2 Geeklog Geeklog 1.3.7 sr1 Geeklog Geeklog 1.3.7 Geeklog Geeklog 1.3.5 sr2 Geeklog Geeklog 1.3.5 sr1 Geeklog Geeklog 1.3.5 Geeklog Geeklog 1.3 |
| Not Vulnerable: |
Geeklog Geeklog 1.3.11 sr1 |
Discussion
Geeklog User Comment Retrieval SQL Injection Vulnerability
Geeklog is susceptible to an SQL injection vulnerability.
The problem occurs in the user comment retrieval functionality of the affected application.
An attacker can exploit this issue to manipulate and inject SQL queries into the underlying database. It may be possible to leverage this issue to steal database contents including user credentials as well as to attack the underlying database.
Geeklog 1.3.11 and prior versions are affected.
Geeklog is susceptible to an SQL injection vulnerability.
The problem occurs in the user comment retrieval functionality of the affected application.
An attacker can exploit this issue to manipulate and inject SQL queries into the underlying database. It may be possible to leverage this issue to steal database contents including user credentials as well as to attack the underlying database.
Geeklog 1.3.11 and prior versions are affected.
Exploit / POC
Geeklog User Comment Retrieval SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Geeklog User Comment Retrieval SQL Injection Vulnerability
Solution:
The vendor has released updates for Geeklog 1.3.11 and Geeklog 1.3.9sr3.
Geeklog Geeklog 1.3.11
Geeklog Geeklog 1.3.9 sr3
Solution:
The vendor has released updates for Geeklog 1.3.11 and Geeklog 1.3.9sr3.
Geeklog Geeklog 1.3.11
-
Geeklog Security Update for Geeklog 1.3.11
http://www.geeklog.net/filemgmt/visit.php?lid=573
Geeklog Geeklog 1.3.9 sr3
-
Geeklog Security Update for Geeklog 1.3.9sr3
http://www.geeklog.net/filemgmt/visit.php?lid=572