iXmail Index.PHP Authentication Bypass SQL Injection Vulnerability
BID:8047
Info
iXmail Index.PHP Authentication Bypass SQL Injection Vulnerability
| Bugtraq ID: | 8047 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2003 12:00AM |
| Updated: | Jun 26 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to frog-m@n <[email protected]>. |
| Vulnerable: |
a-suivre.net iXmail 0.3 a-suivre.net iXmail 0.2 |
| Not Vulnerable: | |
Discussion
iXmail Index.PHP Authentication Bypass SQL Injection Vulnerability
iXmail Index.PHP script has been reported prone to an SQL injection vulnerability.
The issue presents itself, under some circumstances. A remote user may inject arbitrary SQL code via the URI parameters to bypass the iXmail authentication procedure. It has also been demonstrated that this vulnerability may be exploited to disclose sensitive information.
iXmail Index.PHP script has been reported prone to an SQL injection vulnerability.
The issue presents itself, under some circumstances. A remote user may inject arbitrary SQL code via the URI parameters to bypass the iXmail authentication procedure. It has also been demonstrated that this vulnerability may be exploited to disclose sensitive information.
Exploit / POC
iXmail Index.PHP Authentication Bypass SQL Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
iXmail Index.PHP Authentication Bypass SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.