MySQL Eventum Multiple SQL Injection Vulnerabilities
BID:14437
Info
MySQL Eventum Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 14437 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2005 12:00AM |
| Updated: | Aug 01 2005 12:00AM |
| Credit: | James Bercegay of the GulfTech Security Research Team is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
MySQL AB Eventum 1.5.5 MySQL AB Eventum 1.5.4 MySQL AB Eventum 1.4 MySQL AB Eventum 1.3.1 MySQL AB Eventum 1.3 MySQL AB Eventum 1.2.2 MySQL AB Eventum 1.2.1 MySQL AB Eventum 1.2 MySQL AB Eventum 1.1 |
| Not Vulnerable: |
MySQL AB Eventum 1.6 |
Discussion
MySQL Eventum Multiple SQL Injection Vulnerabilities
MySQL Eventum is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
MySQL Eventum is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
MySQL Eventum Multiple SQL Injection Vulnerabilities
No exploit is required.
The following exploit is available:
No exploit is required.
The following exploit is available:
Solution / Fix
MySQL Eventum Multiple SQL Injection Vulnerabilities
Solution:
The vendor has addressed these issues in MySQL Eventum version 1.6.0:
MySQL AB Eventum 1.1
MySQL AB Eventum 1.2
MySQL AB Eventum 1.2.1
MySQL AB Eventum 1.2.2
MySQL AB Eventum 1.3
MySQL AB Eventum 1.3.1
MySQL AB Eventum 1.4
MySQL AB Eventum 1.5.4
MySQL AB Eventum 1.5.5
Solution:
The vendor has addressed these issues in MySQL Eventum version 1.6.0:
MySQL AB Eventum 1.1
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.2
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.2.1
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.2.2
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.3
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.3.1
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.4
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.5.4
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
MySQL AB Eventum 1.5.5
-
MySQL AB eventum-1.6.0.tar.gz
http://dev.mysql.com/get/Downloads/eventum/eventum-1.6.0.tar.gz/from/p ick
References
MySQL Eventum Multiple SQL Injection Vulnerabilities
References:
References:
- Eventum 1.6.0 Released (MySQL AB)
- Eventum Home Page (MySQL AB)
- MySQL Eventum Multiple Vulnerabilities (GulfTech Research)
- MySQL Eventum SQL Injection Exploit (milw0rm)