Uni-vert PhpLeague Joueurs.PHP SQL Injection Vulnerability
BID:19880
CVE-2006-4643 |Info
Uni-vert PhpLeague Joueurs.PHP SQL Injection Vulnerability
| Bugtraq ID: | 19880 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2006 12:00AM |
| Updated: | Sep 07 2006 09:53PM |
| Credit: | DrEiNsTeIn is credited with the discovery of this vulnerability. |
| Vulnerable: |
Uni-Vert PhpLeague 0.82b Uni-Vert PhpLeague 0.82 |
| Not Vulnerable: | |
Discussion
Uni-vert PhpLeague Joueurs.PHP SQL Injection Vulnerability
Uni-vert PhpLeague is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
This issue may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Versions 0.82b and 0.82 are vulnerable; other versions may also be affected.
Uni-vert PhpLeague is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
This issue may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Versions 0.82b and 0.82 are vulnerable; other versions may also be affected.
Exploit / POC
Uni-vert PhpLeague Joueurs.PHP SQL Injection Vulnerability
An attacker can exploit this issue with a web client.
The following proof-of-concept URI is available:
An attacker can exploit this issue with a web client.
The following proof-of-concept URI is available:
Solution / Fix
Uni-vert PhpLeague Joueurs.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].