Geeklog pid CGI Variable SQL Injection Vulnerability
BID:4968
Info
Geeklog pid CGI Variable SQL Injection Vulnerability
| Bugtraq ID: | 4968 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0963 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovered by Ahmet Sabri ALPER <[email protected]> |
| Vulnerable: |
Geeklog Geeklog 1.3.5 |
| Not Vulnerable: |
Geeklog Geeklog 1.3.5 sr1 |
Discussion
Geeklog pid CGI Variable SQL Injection Vulnerability
Geeklog does not properly validate externally-supplied input used in SQL queries. As a result, attackers may be able to modify SQL queries performed by the application by including special characters and additional SQL commands in supplied input.
Exploitation of this vulnerability may result in data corruption, disclosure of sensitive information and intrusion into the database server.
This issue has been reported in version 1.3.5, earlier versions may be susceptible to this issue as well.
Geeklog does not properly validate externally-supplied input used in SQL queries. As a result, attackers may be able to modify SQL queries performed by the application by including special characters and additional SQL commands in supplied input.
Exploitation of this vulnerability may result in data corruption, disclosure of sensitive information and intrusion into the database server.
This issue has been reported in version 1.3.5, earlier versions may be susceptible to this issue as well.
Exploit / POC
Geeklog pid CGI Variable SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Geeklog pid CGI Variable SQL Injection Vulnerability
Solution:
This issue has been addressed in Geeklog 1.3.5 sr1:
Geeklog Geeklog 1.3.5
Solution:
This issue has been addressed in Geeklog 1.3.5 sr1:
Geeklog Geeklog 1.3.5
-
Geeklog geeklog-1.3.5sr1
http://prdownloads.sourceforge.net/geeklog/geeklog-1.3.5sr1.tar.gz