[FYI] SQL Injection in Confixx bis einschließlich 3.0.8

Plesk, Confixx, Froxlor, SysCP, SeCoTo, IspCP, etc.
Post Reply
Roger Wilco
Posts: 5923
Joined: 2004-05-23 12:53
 

[FYI] SQL Injection in Confixx bis einschließlich 3.0.8

Post by Roger Wilco »

Da ja doch noch einige Confixx einsetzen, könnte die folgende auf Bugtraq veröffentlichte Mail interessant sein:
BugTraq wrote:Sql injection is possbile with reseller rights:
i.e. it is possible to enter '# in the "change user" field.
as result you get a list of all added users on the server. With
a special malformed string it is possible
to execute any sql command as confixx mysql user
to the confixx database.

Vendor was informed about over a month ago, while 3.06 was
up to date. 3.08 was released, bug still exists.
Post Reply