SVadvisory#13 ******************************* title: SQL injection product: MYFAQ version: V1.0 site: http://vpontier.free.fr/ ******************************* ===================================================================================== Vulnerability ============== 1) affichagefaq.php3 Code: -------------------------- Variable $Theme, $SousTheme, $Question is not filtered on presence dangerous symbol that can bring about SQL injection. ======================================================================================= 2) choixsoustheme.php3 code: ---------------------------- In the same way in file choixsoustheme.php3, variable $Theme is not filtered on presence dangerous symbol that can bring about SQL injection ======================================================================================= 3) consultation.php3 code: -------------------------- Variable $Theme, $SousTheme are not filtered on presence dangerous symbol, >From - for this appears criticality SQL injection ======================================================================================= 4) inssolution.php3 code: ------------------------- Variable $Faq is not filtered on presence dangerous symbol that brings about criticality SQL injection ======================================================================================= In the same way in following file variable $Theme, $SousTheme and $Faq are not filtered on presence dangerous symbol: $Theme $SousTheme $Faq ------------------ ------------------ ------------------ insfaq.php3 insfaq.php3 saisiefaq.php3 inssoustheme.php3 inssoustheme.php3 voirfaq.php3 instheme.php3 saisiefaq.php3 saisiefaqtotale.php3 saisiefaqtotale.php3 saisiesoustheme.php3 voirfaq.php3 voirfaq.php3 ======================================================================================= More new versions does not contain these criticality ======================================================================================= Bug found ========= CENSORED ~ Search Vulnerabilities Team ~ http://svt.nukleon.us