[38562] in bugtraq
Sql Injection in Confixx 3.06 & 3.08 & 3.?? ?
daemon@ATHENA.MIT.EDU (Erich Klaus)
Mon Apr 25 13:11:36 2005
Date: Mon, 25 Apr 2005 14:54:20 +0200 (MEST)
From: "Erich Klaus" <DR.erich@gmx.net>
To: bugtraq@securityfocus.com
MIME-Version: 1.0
Message-ID: <22133.1114433660@www40.gmx.net>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sql injection is possbile with reseller rights:
i.e. it is possible to enter '# in the "change user" field.
as result you get a list of all added users on the server. With
a special malformed string it is possible
to execute any sql command as confixx mysql user
to the confixx database.
Vendor was informed about over a month ago, while 3.06 was
up to date. 3.08 was released, bug still exists.
--
+++ GMX - die erste Adresse für Mail, Message, More +++
10 GB Mailbox, 100 FreeSMS http://www.gmx.net/de/go/topmail