Community Wizard SQL Injection Vulnerability
BID:6444
Info
Community Wizard SQL Injection Vulnerability
| Bugtraq ID: | 6444 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2002 12:00AM |
| Updated: | Dec 19 2002 12:00AM |
| Credit: | Discovered by Mask_NBTA <[email protected]>. |
| Vulnerable: |
SepCity Community Wizard 4.9 |
| Not Vulnerable: | |
Discussion
Community Wizard SQL Injection Vulnerability
A vulnerability in Community Wizard has been reported. The login component is reportedly susceptible to a SQL-injection attack due to a lack of input validation. Attackers may exploit this vulnerability to manipulate the logic of SQL queries such that they can authenticate successfully without providing appropriate credentials. Other attacks may also be possible.
A vulnerability in Community Wizard has been reported. The login component is reportedly susceptible to a SQL-injection attack due to a lack of input validation. Attackers may exploit this vulnerability to manipulate the logic of SQL queries such that they can authenticate successfully without providing appropriate credentials. Other attacks may also be possible.
Exploit / POC
Community Wizard SQL Injection Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Community Wizard SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.