|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Land Down Under (LDU) contains a flaw that may allow a remote attacker to carry out an SQL injection attack. The issue is due to the 'forums.php' script not properly sanitizing user-supplied input to the 's', 'x', 'n' and 'm' variables. This may allow a remote attacker to inject or manipulate SQL queries in the backend database.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Rumored / Private
OSVDB:
Web Related
|
|
Technical |
The vendor has disputed this issue saying "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected." Subsequent posts to security mail lists and lack of followup or technical details suggest Land Down Under may be prone to XSS or SQL Injection attacks.
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Land Down Under (LDU)
 |
800 |
|
|
|
|
|
|
|
Credit |
- bl2k - bl2k
shabgard.org -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|