Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BPG Multiple Products Vjob Parameter SQL Injection Vulnerability

BPG Easy Publisher and Smart Publisher Pro are prone to an SQL-injection vulnerability because the applications fail to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the applications, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

BPG Easy Publisher and Smart Publisher Pro version 2.77 are vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus