Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Advisory: SQL-Injections in Mapbender Mar 11 2008 11:35AM
RedTeam Pentesting GmbH (release redteam-pentesting de)
Advisory: SQL-Injections in Mapbender

During a penetration test RedTeam Pentesting discovered multiple
SQL-Injections in Mapbender. A remote attacker is able to execute
arbitrary SQL commands and therefore can get e.g. valid usernames and
password hashes of the Mapbender users.

Details
=======

P...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus