ZH2004-14SA (security advisory):Sql Injection in Infinity WEB

"D'Amato Luigi" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.announce
Message-ID <00d401c45c36$3da242d0$2900a8c0@portatile>
06/27/2004

Vendor contacted: June 1st 2004
Published: June 26th 2004
Title: Infinity WEB
Vulnerable versions :1.0 unpatched

Type: Sql Injection

Author: D'Amato Luigi from Zone-h Security Labs -
[email protected] - [email protected]

Vendor: http://www.websoft.it/


Description

**********
Zone-H Security Team has discovered a security flaw in Infinity WEB . This
vulnerability could allow malicious attackers to bypass the authentication
mechanish without having an account.

Details

********************************************

Due to an improper login validation in the login page it is possible to
bypass the authentication mechanism

Solution

**********

The vendor has been contacted and has released a patch


--- 

D'Amato Luigi from Zone-h Security Labs -
[email protected] -
[email protected]
Admin Security Wireless
http://www.securitywireless.info




http://www.zone-h.org/en/advisories/read/id=4892/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.