Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Xoops Remote SQL Injection Vulnerability

Xoops is open-source, freely available web portal software written in object-oriented PHP. It is back-ended by a MySQL database and will run on most Unix and Linux distributions.

The script userinfo.php fails to properly sanatize user input supplied to a SQL statement. It is possible to modify the SQL statement, possibly resulting in the disclosure of sensitive information. Error messages reported may leak additional information about the structure of the query.







 

Privacy Statement
Copyright 2008, SecurityFocus