Land Down Under Auth.PHP SQL Injection Vulnerability
BID:9168
Info
Land Down Under Auth.PHP SQL Injection Vulnerability
| Bugtraq ID: | 9168 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2003 12:00AM |
| Updated: | Dec 08 2003 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Land Down Under Land Down Under 601 |
| Not Vulnerable: |
Land Down Under Land Down Under 602 |
Discussion
Land Down Under Auth.PHP SQL Injection Vulnerability
Land Down Under is prone to SQL injection attacks. This is due to an input validation error in the 'auth.php' script, which will permit remote attackers to influence database queries. This could be used to bypass authentication or mount other attacks against the software or the underlying database.
** A proof-of-concept was included in the initial vulnerability report that does not appear to work due to the software forcing authentication afterwards. However, this does not eliminate the risk of this issue since it is still possible for a remote attacker to influence SQL queries on vulnerable versions.
Land Down Under is prone to SQL injection attacks. This is due to an input validation error in the 'auth.php' script, which will permit remote attackers to influence database queries. This could be used to bypass authentication or mount other attacks against the software or the underlying database.
** A proof-of-concept was included in the initial vulnerability report that does not appear to work due to the software forcing authentication afterwards. However, this does not eliminate the risk of this issue since it is still possible for a remote attacker to influence SQL queries on vulnerable versions.
Exploit / POC
Solution / Fix
References
Land Down Under Auth.PHP SQL Injection Vulnerability
References:
References:
- Land Down Under Homepage (Land Down Under)
- Land Down Under 601 (
)