Mini SQL w3-msql Vulnerability
BID:591
Info
Mini SQL w3-msql Vulnerability
| Bugtraq ID: | 591 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 1999 12:00AM |
| Updated: | Aug 18 1999 12:00AM |
| Credit: | This vulnerability was posted to the Bugtraq mailing list by Gregory Duchemin <[email protected]> on Tue, 17 Aug. |
| Vulnerable: |
Hughes Technologies Mini SQL (mSQL) 2.0.10 Hughes Technologies Mini SQL (mSQL) 2.0 |
| Not Vulnerable: |
Hughes Technologies Mini SQL (mSQL) 2.0.11 |
Exploit / POC
Mini SQL w3-msql Vulnerability
First Approach:
This attack requires the attacker to know the location/directory structure of the site she is attacking.
http://www.victim.org/cgi-bin/w3-msql/protected-directory/private-file
Second Approach:
This approach will gain the intruder a DES encrypted password which they can then attempt to crack it via any number of popular cracking utilites.
http://www.victim.org/cgi-bin/w3-msql/protected-directory/.htpasswd
First Approach:
This attack requires the attacker to know the location/directory structure of the site she is attacking.
http://www.victim.org/cgi-bin/w3-msql/protected-directory/private-file
Second Approach:
This approach will gain the intruder a DES encrypted password which they can then attempt to crack it via any number of popular cracking utilites.
http://www.victim.org/cgi-bin/w3-msql/protected-directory/.htpasswd
Solution / Fix
Mini SQL w3-msql Vulnerability
Solution:
Version 2.0.11 of the Mini SQL Server contains a fix for this problem. Please see the attached support page in the 'Credit' section for more details.
Solution:
Version 2.0.11 of the Mini SQL Server contains a fix for this problem. Please see the attached support page in the 'Credit' section for more details.