TWIG Webmail SQL Query Modification Vulnerability
BID:2791
Info
TWIG Webmail SQL Query Modification Vulnerability
| Bugtraq ID: | 2791 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1348 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was discovered by Luki Rustianto <[email protected]> and pubished on May 28, 2001. |
| Vulnerable: |
TWIG TWIG 2.6.1 TWIG TWIG 2.6 TWIG TWIG 2.5.1 TWIG TWIG 2.5 TWIG TWIG 2.4 TWIG TWIG 2.3.2 TWIG TWIG 2.3.1 TWIG TWIG 2.3 TWIG TWIG 2.2.3 TWIG TWIG 2.2.2 TWIG TWIG 2.2.1 TWIG TWIG 2.2 TWIG TWIG 2.1.1 TWIG TWIG 2.1 TWIG TWIG 2.0.3 TWIG TWIG 2.0.2 TWIG TWIG 2.0.1 TWIG TWIG 2.0 beta3 TWIG TWIG 2.0 beta2 TWIG TWIG 2.0 beta1 TWIG TWIG 2.0 |
| Not Vulnerable: | |
Discussion
TWIG Webmail SQL Query Modification Vulnerability
TWIG Webmail contains a vulnerability which may allow for users to modify SQL queries.
The application fails to quote form variables when they are included in SQL query strings. As a result, it may be possible for malicious clients to inject SQL code into queries that alters the logic of the query. These modified queries may then perform unauthorized operations.
TWIG Webmail contains a vulnerability which may allow for users to modify SQL queries.
The application fails to quote form variables when they are included in SQL query strings. As a result, it may be possible for malicious clients to inject SQL code into queries that alters the logic of the query. These modified queries may then perform unauthorized operations.
Exploit / POC
TWIG Webmail SQL Query Modification Vulnerability
These vulnerabilities can be exploited with a web browser.
These vulnerabilities can be exploited with a web browser.
Solution / Fix
TWIG Webmail SQL Query Modification Vulnerability
Solution:
It is advised that if TWIG Webmail is to remain in use, administrators should fix the query strings manually. The vulnerability can be patched if quotes are added around variables in query strings.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is advised that if TWIG Webmail is to remain in use, administrators should fix the query strings manually. The vulnerability can be patched if quotes are added around variables in query strings.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.