-
Secunia Advisory 16315
SilverNews Usename SQL Injection Vulnerability- Criticality: High
- Description: rgod has discovered a vulnerability in SilverNews, which can be exploited by malicious people to conduct SQL injection attacks and compromise a vulnerable system.
Input passed to the username in the administration login isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
This can further be exploited to bypass the authentication process and access the administration section where PHP code can be injected in templates.
- Secunia Advisory: http://secunia.com/advisories/16315/
