SmE FileMailer login form SQL injection
| smefilemailer-login-sql-injection (31533) |
Description:
SmE FileMailer is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the index.php or the dl.php script using the ps, us, f or code parameters, which could allow the attacker to view, add, modify or delete information in the back-end database.
Platforms Affected:
- scriptme, SmE FileMailer 1.21
Remedy:
No remedy available as of June 27, 2009.
Consequences:
Data Manipulation
References:
- Full-Disclosure Mailing List, Tue Jan 16 2007 - 12:19:36 CST, [x0n3-h4ck] SMe FileMailer 1.21 Remote Sql Injection Exploit at http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0316.html.
- HotScripts Web site, SmE FileMailer at http://www.hotscripts.com/Detailed/22972.html.
- BID-22081: Scriptme SmE File Mailer Login SQL Injection Vulnerability
- CVE-2007-0339: SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter). NOTE: some of these details are obtained from third party information.
- CVE-2007-0346: SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter.
- CVE-2007-0350: Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346.
- SA23766: SmE FileMailer "ps" SQL Injection Vulnerability
- VUPEN/ADV-2007-0221: SmE FileMailer Multiple Parameter Handling Remote SQL Query Injection Vulnerabilities
Reported:
Jan 16, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
