source: http://www.securityfocus.com/bid/6455/info Several vulnerabilities have been discovered in SPGPartenaires. The vulnerabilities are due to insufficient sanitization of the 'pass' and 'SPGP' variables used to construct SQL queries in various PHP scripts. By exploiting these issues it is possible to modify the logic of SQL queries through malformed query strings in requests for the vulnerable script. By injecting SQL code into the 'pass' or 'SPGP' variable, it may be possible for an attacker to corrupt member information. It may also be possible for attackers to perform more advanced attacks on the underlying database. http://www.example.com/modif/ident.php?id=[MEMBERID]&pass='%20OR%20''='
Related ExploitsTrying to match OSVDBs (1): 4534
Other Possible E-DB Search Terms: SPGPartenaires 3.0.1, SPGPartenaires
|2002-12-20||SPGPartenaires 3.0.1 - 'delete.php' SQL Injection||frog|