PHPSurveyor SID Parameter SQL Injection Vulnerability
BID:16077
Info
PHPSurveyor SID Parameter SQL Injection Vulnerability
| Bugtraq ID: | 16077 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 28 2005 12:00AM |
| Updated: | Dec 28 2005 12:00AM |
| Credit: | Discovered by taqua. |
| Vulnerable: |
PHPSurveyor PHPSurveyor 0.99 |
| Not Vulnerable: |
PHPSurveyor PHPSurveyor 0.991 |
Discussion
PHPSurveyor SID Parameter SQL Injection Vulnerability
PHPSurveyor is prone to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
PHPSurveyor 0.99 is vulnerable to this issue.
PHPSurveyor is prone to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
PHPSurveyor 0.99 is vulnerable to this issue.
Exploit / POC
PHPSurveyor SID Parameter SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PHPSurveyor SID Parameter SQL Injection Vulnerability
Solution:
The vendor has released PHPSurveyor 0.991 to address this issue.
PHPSurveyor PHPSurveyor 0.99
Solution:
The vendor has released PHPSurveyor 0.991 to address this issue.
PHPSurveyor PHPSurveyor 0.99
-
PHPSurveyor phpsurveyor-0_991.zip
http://prdownloads.sourceforge.net/phpsurveyor/phpsurveyor-0_991.zip?d ownload
References
PHPSurveyor SID Parameter SQL Injection Vulnerability
References:
References:
- PHPSurveyor Home Page (PHPSurveyor)