Zoph Multiple SQL Injection Vulnerabilities
BID:30298
Info
Zoph Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 30298 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3258 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2008 12:00AM |
| Updated: | May 07 2015 05:27PM |
| Credit: | Zoph |
| Vulnerable: |
Zoph Zoph 0.7 4 Zoph Zoph 0.7 1 Zoph Zoph 0.7 |
| Not Vulnerable: |
Zoph Zoph 0.7 5 |
Discussion
Zoph Multiple SQL Injection Vulnerabilities
Zoph is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Zoph 0.7.0.5 are vulnerable.
Zoph is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Zoph 0.7.0.5 are vulnerable.
Exploit / POC
Zoph Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Zoph Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Zoph Zoph 0.7
Zoph Zoph 0.7 4
Zoph Zoph 0.7 1
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Zoph Zoph 0.7
-
Zoph zoph-0.7.0.5.tar.gz
http://downloads.sourceforge.net/zoph/zoph-0.7.0.5.tar.gz?modtime=1216 591842&big_mirror=0
Zoph Zoph 0.7 4
-
Zoph zoph-0.7.0.5.tar.gz
http://downloads.sourceforge.net/zoph/zoph-0.7.0.5.tar.gz?modtime=1216 591842&big_mirror=0
Zoph Zoph 0.7 1
-
Zoph zoph-0.7.0.5.tar.gz
http://downloads.sourceforge.net/zoph/zoph-0.7.0.5.tar.gz?modtime=1216 591842&big_mirror=0
References
Zoph Multiple SQL Injection Vulnerabilities
References:
References:
- Zoph 0.7.0.5 Changelog (Zoph)
- Zoph Homepage (Zoph)