Deadlock Multiple Unspecified SQL Injection Vulnerabilities
BID:22023
Info
Deadlock Multiple Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 22023 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2007 12:00AM |
| Updated: | Jan 12 2007 10:10PM |
| Credit: | The vendor reported these vulnerabilities. |
| Vulnerable: |
Deadlock Deadlock 0.64 Deadlock Deadlock 0.63 |
| Not Vulnerable: |
Deadlock Deadlock 1.0 |
Discussion
Deadlock Multiple Unspecified SQL Injection Vulnerabilities
Deadlock is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Very little information is known about this issue. This BID will be updated as soon as more information becomes available.
These issues affect Deadlock 0.64 and prior versions.
Deadlock is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Very little information is known about this issue. This BID will be updated as soon as more information becomes available.
These issues affect Deadlock 0.64 and prior versions.
Exploit / POC
Deadlock Multiple Unspecified SQL Injection Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
Deadlock Multiple Unspecified SQL Injection Vulnerabilities
Solution:
The vendor has released version 1.0 to address these issues; please see the reference section for details.
Deadlock Deadlock 0.63
Deadlock Deadlock 0.64
Solution:
The vendor has released version 1.0 to address these issues; please see the reference section for details.
Deadlock Deadlock 0.63
-
Deadlock Deadlock 1.0
http://www.phpdeadlock.org/download.php
Deadlock Deadlock 0.64
-
Deadlock Deadlock 1.0
http://www.phpdeadlock.org/download.php
References
Deadlock Multiple Unspecified SQL Injection Vulnerabilities
References:
References:
- Deadlock Web Site (Deadlock)