Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: [eVuln] phpNewsManager Multiple SQL Injections

[eVuln] phpNewsManager Multiple SQL Injections

From: <alex_at_evuln.com>
Date: 8 Apr 2006 11:23:08 -0000
('binary' encoding is not supported, stored as-is) New eVuln Advisory:
phpNewsManager Multiple SQL Injections
http://evuln.com/vulns/110/summary.html

--------------------Summary----------------
eVuln ID: EV0110
CVE: CVE-2006-1560
Vendor: SkinTech Group
Vendor's Web Site: http://www.skintech.org/
Software: phpNewsManager
Versions: 1.48
Critical Level: Moderate
Type: SQL Injection
Class: Remote
Status: Unpatched. No reply from developer(s)
PoC/Exploit: Not Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)

-----------------Description---------------
All user-defined variables are not properly sanitized before being used in SQL queries. This can be used to bypass authentication or make any SQL query by injecting arbitrary SQL code.

Vulnerable scripts:
browse.php
category.php
gallery.php
poll.php
...

--------------PoC/Exploit----------------------
Waiting for developer(s) reply.
If there is no reply exploitation code will be published in 10 days
http://evuln.com/vulns/110/exploit.html

--------------Solution---------------------
No Patch available.

--------------Credit-----------------------
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)

Regards,
Aliaksandr Hartsuyeu
http://evuln.com - Penetration Testing Services
.
Received on Apr 09 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]