DUware Multiple Software SQL Injection Vulnerability
BID:15681
Info
DUware Multiple Software SQL Injection Vulnerability
| Bugtraq ID: | 15681 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2005 12:00AM |
| Updated: | Dec 04 2006 06:09PM |
| Credit: | syst3m_f4ult of the Crouz Security Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
DUWare DUpaypal Pro 3.1 DUWare DUpaypal Pro 3.0 DUware DUpaypal 3.1 DUware DUpaypal 3.0 DUware DUnews 1.1 DUware DUnews 1.0 DUware DUgallery 3.3 DUware DUgallery 3.2 DUware DUgallery 3.1 DUware DUgallery 3.0 DUware DUdownload 1.1 DUware DUdownload 1.0 DUware DUdirectory Pro SQL 3.1 DUware DUdirectory Pro SQL 3.0 DUware DUdirectory Pro 3.1 DUware DUdirectory Pro 3.0 DUware DUdirectory 3.1 DUware DUdirectory 3.0 DUware DUclassified 4.2 DUware DUclassified 4.1 DUware DUclassified 4.0 DUware DUarticle 1.1 DUware DUarticle 1.0 DUware DUamazon 3.1 DUware DUamazon 3.0 |
| Not Vulnerable: | |
Discussion
DUware Multiple Software SQL Injection Vulnerability
Multiple DUware applications are prone to an SQL-injection vulnerability because they fail to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Multiple DUware applications are prone to an SQL-injection vulnerability because they fail to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
DUware Multiple Software SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
DUware Multiple Software SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
DUware Multiple Software SQL Injection Vulnerability
References:
References:
- DUware Homepage (DUware)
- [Aria-Security Team] DuWare DuDownloads SQL Injection Vuln (Aria-Security)
- [Aria-Security Team] DuWare DuNews SQL Injection Vuln (Aria-Security)
- [Aria-Security Team] DuWare DuPaypal SQL Injection Vuln (Aria-Security)