MyAuth3 'pass' Parameter SQL Injection Vulnerability
BID:49530
Info
MyAuth3 'pass' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 49530 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2011 12:00AM |
| Updated: | Sep 08 2011 12:00AM |
| Credit: | Marcio Almeida |
| Vulnerable: |
MyAuth3 MyAuth3 3.0 |
| Not Vulnerable: | |
Discussion
MyAuth3 'pass' Parameter SQL Injection Vulnerability
MyAuth3 is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
MyAuth3 3.0 is vulnerable; other versions may also be affected.
MyAuth3 is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
MyAuth3 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
MyAuth3 'pass' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit is available:
Attackers can use a browser to exploit this issue.
The following exploit is available:
Solution / Fix
MyAuth3 'pass' Parameter SQL Injection Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
MyAuth3 'pass' Parameter SQL Injection Vulnerability
References:
References:
- MyAuth3 Blind SQL Injection (MyAuth3)