Freeway Multiple SQL Injection Vulnerabilities
BID:31508
Info
Freeway Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 31508 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6013 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Freeway Project |
| Vulnerable: |
Freeway Project Freeway 1.4.2 .197 Freeway Project Freeway 1.4.1 .171 |
| Not Vulnerable: |
Freeway Project Freeway 1.4.3.210 |
Discussion
Freeway Multiple SQL Injection Vulnerabilities
Freeway is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect versions prior to Freeway 1.4.3.210.
Freeway is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect versions prior to Freeway 1.4.3.210.
Exploit / POC
Freeway Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Freeway Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released Freeway 1.4.3.210 to address this issue. Please see the references for more information.
Solution:
The vendor has released Freeway 1.4.3.210 to address this issue. Please see the references for more information.
References
Freeway Multiple SQL Injection Vulnerabilities
References:
References:
- Freeway 1.4.3.210 Change Log (Freeway Project)
- Freeway Homepage (Freeway Project)