what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

coWiki 0.3.4 SQL Injection

coWiki 0.3.4 SQL Injection
Posted Jul 22, 2010
Authored by MustLive

coWiki versions 0.3.4 and below suffer from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | c9d51e1abda92629bec518aa2b18143d37b63bea8e78f7e93fefc1aa3d61047c

coWiki 0.3.4 SQL Injection

Change Mirror Download
Hello Full-Disclosure!

I want to warn you about security vulnerability in coWiki.

Earlier I already wrote about XSS vulnerability in coWiki -
SecurityVulns ID:8005 (http://securityvulns.ru/Rdocument692.html).

-----------------------------
Advisory: SQL Injection vulnerability in coWiki
-----------------------------
URL: http://websecurity.com.ua/3496/
-----------------------------
Affected products: coWiki 0.3.4 and previous versions.
-----------------------------
Timeline:

23.01.2009 - found vulnerability.
12.09.2009 - announced at my site. After which I informed developers (both
original developer and maintainer), but they didn't answer.
21.07.2010 - disclosed at my site.
-----------------------------
Details:

This is SQL Injection vulnerability.

SQL Injection:

http://site/index.php?node=-1'%20or%20version()%3E’5

Already when I informed developers in 2007 about XSS hole, they answered me
that they didn't support this engine any more. So users of this system must
fix this hole by themselves (as previous one).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua


Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close