Peel rubid Parameter SQL Injection Vulnerability
BID:15415
Info
Peel rubid Parameter SQL Injection Vulnerability
| Bugtraq ID: | 15415 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2005 12:00AM |
| Updated: | Nov 14 2005 12:00AM |
| Credit: | Discovered by r0t. |
| Vulnerable: |
PEEL PEEL 2.7 PEEL PEEL 2.6 |
| Not Vulnerable: | |
Discussion
Peel rubid Parameter SQL Injection Vulnerability
Peel is prone to a SQL injection vulnerability. This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Peel 2.6 and 2.7 are reported to be vulnerable. Other versions may also be affected.
Peel is prone to a SQL injection vulnerability. This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Peel 2.6 and 2.7 are reported to be vulnerable. Other versions may also be affected.
Exploit / POC
Peel rubid Parameter SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Peel rubid Parameter SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.