Segue CMS Unspecified SQL Injection Vulnerability
BID:20645
Info
Segue CMS Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 20645 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2006 12:00AM |
| Updated: | Oct 23 2006 06:33PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Segue CMS Segue CMS 1.5.7 |
| Not Vulnerable: |
Segue CMS Segue CMS 1.5.8 |
Discussion
Segue CMS Unspecified SQL Injection Vulnerability
Segue CMS is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects versions prior to 1.5.8.
Segue CMS is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
This issue affects versions prior to 1.5.8.
Exploit / POC
Segue CMS Unspecified SQL Injection Vulnerability
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
Segue CMS Unspecified SQL Injection Vulnerability
Solution:
The vendor has released an update that addresses this issue. Please the referenced advisories for more information.
Segue CMS Segue CMS 1.5.7
Solution:
The vendor has released an update that addresses this issue. Please the referenced advisories for more information.
Segue CMS Segue CMS 1.5.7
-
Segue CMS Segue CMS version 1.5.8
http://sourceforge.net/project/showfiles.php?group_id=82171
References
Segue CMS Unspecified SQL Injection Vulnerability
References:
References:
- Segue CMS 1.5.8 Release Notes (Segue CMS)
- Segue CMS Homepage (Segue CMS)