The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Sql Injection in Confixx 3.06 & 3.08 & 3.?? ?


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Mon, 25 Apr 2005 14:54:20 +0200 (MEST)
From: "Erich Klaus" <DR.erich@gmx.net.>
To: [email protected]
Subject: Sql Injection in Confixx 3.06 & 3.08 & 3.?? ?
X-Priority: 3 (Normal)
X-Authenticated: #2602105
Message-ID: <22133.1114433660@www40.gmx.net.>
X-Mailer: WWW-Mail 1.6 (Global Message Exchange)
X-Flags: 0001
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Virus-Scanned: antivirus-gw at tyumen.ru

Sql injection is possbile with reseller rights:
i.e. it is possible to enter '# in the "change user" field. 
as result you get a list of all added users on the server. With 
a special malformed string it is possible
to execute any sql command as confixx mysql user 
to the confixx database.

Vendor was informed about over a month ago, while 3.06 was
up to date. 3.08 was released, bug still exists.

 

-- 
+++ GMX - die erste Adresse fЭr Mail, Message, More +++

10 GB Mailbox, 100 FreeSMS  http://www.gmx.net/de/go/topmail


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру