b2evolution Multiple SQL Injection Vulnerabilities
BID:8591
Info
b2evolution Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 8591 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2003 12:00AM |
| Updated: | Sep 09 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to office <http://www.office.ac/>. |
| Vulnerable: |
b2evolution b2evolution 0.8.2 |
| Not Vulnerable: | |
Discussion
b2evolution Multiple SQL Injection Vulnerabilities
It has been reported that b2evolution may be prone to multiple SQL injection vulnerabilities that may allow a remote attacker to inject malicious SQL syntax into database queries. The issues are caused due to a failure of the software to sanitize user-supplied input.
Successful exploitation of these issues may allow an attacker to gain access to sensitive information stored in the database. This information may then be used to launch further attacks agianst a vulnerable system.
It has been reported that b2evolution may be prone to multiple SQL injection vulnerabilities that may allow a remote attacker to inject malicious SQL syntax into database queries. The issues are caused due to a failure of the software to sanitize user-supplied input.
Successful exploitation of these issues may allow an attacker to gain access to sensitive information stored in the database. This information may then be used to launch further attacks agianst a vulnerable system.
Exploit / POC
b2evolution Multiple SQL Injection Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.