BugTraq wrote:Sql injection is possbile with reseller rights:
i.e. it is possible to enter '# in the "change user" field.
as result you get a list of all added users on the server. With
a special malformed string it is possible
to execute any sql command as confixx mysql user
to the confixx database.
Vendor was informed about over a month ago, while 3.06 was
up to date. 3.08 was released, bug still exists.
[FYI] SQL Injection in Confixx bis einschließlich 3.0.8
-
Roger Wilco
- Posts: 5923
- Joined: 2004-05-23 12:53
[FYI] SQL Injection in Confixx bis einschließlich 3.0.8
Da ja doch noch einige Confixx einsetzen, könnte die folgende auf Bugtraq veröffentlichte Mail interessant sein: