Name:
HTTP.Referer.Header.SQL.Injection
Released Date:
May 7 2008
Severity:
medium
CVE:
2007-1061
Bugtraq:
22638

FortiGuard Center > Vulnerability Encyclopedia


In-Depth Analysis

Description
The web application software is vulnerable to a SQL injection flaw through the HTTP Referer header. A malicious user can thus execute blind SQL queries in the backend database without the user's consent.
 
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
 
Affected Products
PHP-Nuke 8.0.0 Final
Aliases
References
http://www.securityfocus.com/bid/22638
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1061
http://www.milw0rm.com/exploits/3346
Recommended Actions
Update the vulnerable software.

 
 
SITE MAP  |  LEGAL NOTICES

      © 2003 FORTINET INC. ALL RIGHTS RESERVED