smbind 'username' Field SQL Injection Vulnerability
BID:42963
Info
smbind 'username' Field SQL Injection Vulnerability
| Bugtraq ID: | 42963 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2010 12:00AM |
| Updated: | Sep 03 2010 12:00AM |
| Credit: | IHTeam |
| Vulnerable: |
smbind smbind 0.4.7 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: | |
Discussion
smbind 'username' Field SQL Injection Vulnerability
smbind is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
smbind 0.4.7 is vulnerable; other versions may also be affected.
smbind is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
smbind 0.4.7 is vulnerable; other versions may also be affected.
Exploit / POC
smbind 'username' Field SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example input data is available:
Enter in username field: admin'; #
Enter in password field: [anything]
Attackers can use a browser to exploit this issue.
The following example input data is available:
Enter in username field: admin'; #
Enter in password field: [anything]
Solution / Fix
smbind 'username' Field SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 alpha
Debian Linux 5.0 amd64
Debian Linux 5.0 ia-32
Debian Linux 5.0 hppa
Debian Linux 5.0 mips
Debian Linux 5.0 ia-64
Debian Linux 5.0 s/390
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 alpha
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 amd64
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 ia-32
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 hppa
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 mips
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 ia-64
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 s/390
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 m68k
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 arm
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 mipsel
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 powerpc
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 armel
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb
Debian Linux 5.0 sparc
-
Debian smbind_0.4.7-3+lenny1_all.deb
http://security.debian.org/pool/updates/main/s/smbind/smbind_0.4.7-3+l enny1_all.deb