Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Papoo CMS 3.6 - SQL Injection |
|---|---|
| Date: | Sun, 24 Jun 2007 18:20:59 +0200 |
Papoo Content Management System Backend SQL Injection Jun 24 2007 _______________________________________________________________________________ * Product Papoo Content Management System * Vulnerable Versions Papoo 3.6 and maybe prior * Vendor Status The Vendor was notified and the issue was fixed. A patch is available at http://www.papoo.de/index/menuid/204/reporeid/215 * Details The Papoo Content Management System is prone to an SQL Injection that can be exploited by any user with access to the backend system and with privileges to modify the navigation menu. The application will get the read and publish privileges for every usergroup and for every menu item that is meant to be edited and specified by the `selmenuid' GET parameter. It fails to sanitize the value of the parameter. * Impact Attackers may be able to execute arbitrary SQL queries. * Exploit No exploit required. _______________________________________________________________________________ Nico Leidecker - http://www.leidecker.info _____________________________________________________________________ Der WEB.DE SmartSurfer hilft bis zu 70% Ihrer Onlinekosten zu sparen! http://smartsurfer.web.de/?mc=100071&distributionid=000000000066
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Ingres verifydb local stack overflow, NGSSoftware Insight Security Research |
|---|---|
| Next by Date: | Ingres Unauthenticated Pointer Overwrite 1, NGSSoftware Insight Security Research |
| Previous by Thread: | Ingres verifydb local stack overflow, NGSSoftware Insight Security Research |
| Next by Thread: | Ingres Unauthenticated Pointer Overwrite 1, NGSSoftware Insight Security Research |
| Indexes: | [Date] [Thread] [Top] [All Lists] |