Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

TWIG Webmail SQL Query Modification Vulnerability

TWIG Webmail contains a vulnerability which may allow for users to modify SQL queries.

The application fails to quote form variables when they are included in SQL query strings. As a result, it may be possible for malicious clients to inject SQL code into queries that alters the logic of the query. These modified queries may then perform unauthorized operations.







 

Privacy Statement
Copyright 2008, SecurityFocus