PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
BID:14927
Info
PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
| Bugtraq ID: | 14927 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2005 12:00AM |
| Updated: | Sep 23 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpMyFAQ phpMyFAQ 1.5.1 |
| Not Vulnerable: | |
Discussion
PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
phpMyFAQ is affected by an SQL injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input before using it in a SQL query.
This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
phpMyFAQ version 1.5.1 is reported prone to this vulnerability.
phpMyFAQ is affected by an SQL injection vulnerability. This issue is due to the application failing to properly sanitize user-supplied input before using it in a SQL query.
This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
phpMyFAQ version 1.5.1 is reported prone to this vulnerability.
Exploit / POC
PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
No exploit is required.
An example has been provided:
switch to /admin directory, click on "forgotten password" feature
user: ' or isnull(1/0) /*
mail: [your_email]
No exploit is required.
An example has been provided:
switch to /admin directory, click on "forgotten password" feature
user: ' or isnull(1/0) /*
mail: [your_email]
Solution / Fix
PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPMyFAQ Password.PHP SQL Injection Vulnerabililty
References:
References: