BytesFall Explorer Multiple Unspecified SQL Injection Vulnerabilities
BID:20800
Info
BytesFall Explorer Multiple Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 20800 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2006 12:00AM |
| Updated: | Oct 31 2006 09:47PM |
| Credit: | RedTeam Pentesting is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
BytesFall Solutions ByteFall Explorer 0.0.7 BytesFall Solutions ByteFall Explorer 0.0.6 BytesFall Solutions ByteFall Explorer 0.0.4 BytesFall Solutions ByteFall Explorer 0.0.3 BytesFall Solutions ByteFall Explorer 0.0.2 BytesFall Solutions ByteFall Explorer 0.0.1 BytesFall Solutions ByteFall Explorer 0.0.7.1 BytesFall Solutions ByteFall Explorer 0.0.5.1 BytesFall Solutions ByteFall Explorer 0.0.5 |
| Not Vulnerable: |
BytesFall Solutions ByteFall Explorer 0.0.7.2 |
Discussion
BytesFall Explorer Multiple Unspecified SQL Injection Vulnerabilities
BytesFall Explorer is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions prior to 0.0.7.2 are vulnerable to these issues.
BytesFall Explorer is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions prior to 0.0.7.2 are vulnerable to these issues.
Exploit / POC
BytesFall Explorer Multiple Unspecified SQL Injection Vulnerabilities
Attackers can use a web client to exploit these issues.
Attackers can use a web client to exploit these issues.
Solution / Fix
BytesFall Explorer Multiple Unspecified SQL Injection Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
References
BytesFall Explorer Multiple Unspecified SQL Injection Vulnerabilities
References:
References:
- Advisory: Authentication bypass in BytesFall Explorer (RedTeam Pentesting)
- ByteFall Explorer 0.0.7.2 Release Notes (ByteFall Solutions)
- Vendor Home Page (ByteFall Solutions)
- Authentication bypass in BytesFall Explorer (RedTeam Pentesting)