Py-Membres Remote SQL Injection Vulnerability
BID:7301
Info
Py-Membres Remote SQL Injection Vulnerability
| Bugtraq ID: | 7301 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2003 12:00AM |
| Updated: | Apr 07 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Frog-m@n. |
| Vulnerable: |
Py-Membres Py-Membres 4.0 |
| Not Vulnerable: | |
Discussion
Py-Membres Remote SQL Injection Vulnerability
A vulnerability has been reported for Py-Membres 4.0 that allows remote attackers to modify the logic of SQL queries.
It has been reported that an input validation error exists in the login.php file included with Py-Membres. Because of this, a remote attacker may launch SQL injection attacks through the software.
A vulnerability has been reported for Py-Membres 4.0 that allows remote attackers to modify the logic of SQL queries.
It has been reported that an input validation error exists in the login.php file included with Py-Membres. Because of this, a remote attacker may launch SQL injection attacks through the software.
Solution / Fix
Py-Membres Remote SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.