Zoph _Order Multiple SQL Injection Vulnerabilities
BID:24933
Info
Zoph _Order Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 24933 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3905 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2007 12:00AM |
| Updated: | Oct 26 2007 01:26AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Zoph Zoph 0.7 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Zoph Zoph 0.7 1 |
Discussion
Zoph _Order Multiple SQL Injection Vulnerabilities
Zoph is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Zoph is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Zoph _Order Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Zoph _Order Multiple SQL Injection Vulnerabilities
Solution:
The vendor has addressed these issues with an upgrade. Please see the vendor references for details.
Zoph Zoph 0.7
Solution:
The vendor has addressed these issues with an upgrade. Please see the vendor references for details.
Zoph Zoph 0.7
-
Zoph zoph-0.7.0.1.tar.gz
http://downloads.sourceforge.net/zoph/zoph-0.7.0.1.tar.gz?modtime=1184 416988&big_mirror=0