ReadyMedia (MiniDLNA) Multiple SQL Injection Vulnerabilities
BID:61180
Info
ReadyMedia (MiniDLNA) Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 61180 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2013 12:00AM |
| Updated: | Apr 04 2013 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ReadyMedia (MiniDLNA) Multiple SQL Injection Vulnerabilities
ReadyMedia (MiniDLNA) is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to ReadyMedia (MiniDLNA) 1.1.0 are vulnerable.
ReadyMedia (MiniDLNA) is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to ReadyMedia (MiniDLNA) 1.1.0 are vulnerable.
Exploit / POC
ReadyMedia (MiniDLNA) Multiple SQL Injection Vulnerabilities
An attacker can exploit these issues using a web browser.
An attacker can exploit these issues using a web browser.
Solution / Fix
ReadyMedia (MiniDLNA) Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ReadyMedia Multiple SQL Injection Vulnerabilities
References:
References: