by r0t,der4444,cembo,VietMafia

Friday, November 25, 2005

SMBCMS v2.1 SQL injection.

SMBCMS v2.1 SQL injection.
Vuln. dicovered by : r0t
Date: 25 nov. 2005
Vendor:www.smbcms.com
affected vesion: v2.1

Vuln. Description:
SMBCMS search engine contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search feature not properly sanitizing user-supplied input.
This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Solution:
Edit the source code to ensure that input is properly sanitised.

0 Comments:

Post a Comment

<< Home

 
Copyright (c) 2006 Pridels Sec Crew