ZH2004-13SA (security advisory): Sql Injection in Help Desp Pro 2.0

"D'Amato Luigi" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.announce
Message-ID <00f401c45b7e$03562280$2900a8c0@portatile>
26/06/2004

ZH2004-10SA (security advisory): Sql Injection in Help Desp Pro 2.0
Discovered: June 1st 2004

Vendor contacted: June 1st 2004
Published: June 26th 2004

Title: Help Desk Pro

Vulnerable versions :2.0 unpatched

Type: Sql Injection

Author: D'Amato Luigi from Zone-h Security Labs -
[email protected] - [email protected]

Vendor: http://www.websoft.it/


Description

**********
Zone-H Security Team has discovered a flaw in Securityin Help Desk Pro. This
vulnerability could allow malicious
attackers to bypass the authentication mechanish without having an account

Detail

********************************************

Due to an improper login validation in the login page it is possible to
bypass the authentication mechanism

Solution

**********

The vendor has been contacted and has released a patch


--- 

D'Amato Luigi from Zone-h Security Labs -
[email protected] -
[email protected]
Admin Security Wireless
http://www.securitywireless.info

http://www.zone-h.org/en/advisories/read/id=4891/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.