UNU Networks MailGust User_email.PHP SQL Injection Vulnerability
BID:14933
Info
UNU Networks MailGust User_email.PHP SQL Injection Vulnerability
| Bugtraq ID: | 14933 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2005 12:00AM |
| Updated: | Sep 24 2005 12:00AM |
| Credit: | Discovery is credited to <[email protected] >. |
| Vulnerable: |
UNU Networks MailGust 1.9 |
| Not Vulnerable: | |
Discussion
UNU Networks MailGust User_email.PHP SQL Injection Vulnerability
MailGust is prone to an SQL injection vulnerability.
This issue is due to the application failing to properly sanitize user-supplied input to the '/gorum/user_email.php' script before using it in a SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
MailGust 1.9 is reported prone to this vulnerability.
MailGust is prone to an SQL injection vulnerability.
This issue is due to the application failing to properly sanitize user-supplied input to the '/gorum/user_email.php' script before using it in a SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
MailGust 1.9 is reported prone to this vulnerability.
Exploit / POC
UNU Networks MailGust User_email.PHP SQL Injection Vulnerability
An exploit is not required.
The following proof of concept example is available:
An exploit is not required.
The following proof of concept example is available:
Solution / Fix
UNU Networks MailGust User_email.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
UNU Networks MailGust User_email.PHP SQL Injection Vulnerability
References:
References:
- MailGust Product Page (UNU Networks)
- MailGust 1.9 SQL Injection ([email protected])