NoseRub 'identity.php' SQL Injection Vulnerability
BID:27065
Info
NoseRub 'identity.php' SQL Injection Vulnerability
| Bugtraq ID: | 27065 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6602 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Felix Groebert discovered this vulnerability. |
| Vulnerable: |
NoseRub NoseRub 0.5.2 |
| Not Vulnerable: | |
Discussion
NoseRub 'identity.php' SQL Injection Vulnerability
NoseRub is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NoseRub 0.5.2 is vulnerable to this issue; other versions may also be affected.
NoseRub is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NoseRub 0.5.2 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
NoseRub 'identity.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
NoseRub 'identity.php' SQL Injection Vulnerability
Solution:
The vendor has committed a fix to their Subversion repository. Users of affected packages should contact the vendor for information on obtaining and applying fixes.
Solution:
The vendor has committed a fix to their Subversion repository. Users of affected packages should contact the vendor for information on obtaining and applying fixes.
References
NoseRub 'identity.php' SQL Injection Vulnerability
References:
References:
- [Full-disclosure] NoseRub Login SQL Injection Vulnerability (Narf Dude)
- NoseRub Project Page (NoseRub)