[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAPhqm0MNG5n55tSOnWCAmtRY8o6pSKrDSN+=DexEHpQkAaauwA@mail.gmail.com>
Date: Sun, 6 Nov 2011 22:27:59 +0100
From: muuratsalo experimental hack lab <muuratsalo@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: OrderSys <= 1.6.4 Sql Injection Vulnerabilities
Dear All,
I have found multiple sql injection vulnerabilities in OrderSys <= 1.6.4.
The vendor knows the vulnerabilities and he is fixing them as stated
in the enclosed advisory. (See also
http://www.bioinformatics.org/phplabware/labwiki/index.php?page=release_notes)
Since the developer is currently patching the current release it is
possible that you can find in the software link different versions of
the same app (1.6.4).
Best,
muuratsalo
View attachment "ordersys.txt" of type "text/plain" (1645 bytes)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists