UFO2000 SQL Injection Vulnerability
BID:19028
CVE-2006-3792 |Info
UFO2000 SQL Injection Vulnerability
| Bugtraq ID: | 19028 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3792 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Feb 26 2007 06:06PM |
| Credit: | Discovery is credited to Luigi Auriemma. |
| Vulnerable: |
UFO2000 UFO2000 SVN 1057 Gentoo Linux |
| Not Vulnerable: |
UFO2000 UFO2000 SVN 1061 UFO2000 UFO2000 SVN 1058 |
Discussion
UFO2000 SQL Injection Vulnerability
UFO2000 is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
UFO2000 is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
UFO2000 SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
UFO2000 SQL Injection Vulnerability
Solution:
The vendor has released version SVN 1058 to fix some of the most critical issues, and version 1061 to fix the remaining issues. Please visit the vendor site or contact the vendor for more information.
Solution:
The vendor has released version SVN 1058 to fix some of the most critical issues, and version 1061 to fix the remaining issues. Please visit the vendor site or contact the vendor for more information.
References
UFO2000 SQL Injection Vulnerability
References:
References:
- UFO2000 Web Site (UFO2000)
- Multiple vulnerabilities in UFO2000 svn 1057 (Luigi Auriemma
)