Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Fuju News SQL Injection and Authentication Bypass Vulnerabilities

Fuju News is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

Fuju News is also susceptible to an authentication-bypass vulnerability. This issue is due to a design flaw that allows attackers to gain administrative access to the application. A successful exploit could allow an attacker to compromise the application.

Fuju News version 1.0 is vulnerable to these issues. Other versions may be affected as well.







 

Privacy Statement
Copyright 2009, SecurityFocus