[vuln.sg] Vulnerability Research Advisory Cybozu Garoon 2 SQL Injection Vulnerabilities by Tan Chew Keong Release Date: 2006-08-28 Summary ------- Some SQL injection vulnerabilities have been found in Cybozu Garoon 2. When exploited by a logon user, the vulnerabilities allow manipulation of SQL statements which can lead to disclosure of information from the database, or to cause the backend MySQL database to consume large amount of CPU resources. Tested Versions --------------- Cybuzu Garoon 2 Version 2.1.0 for Windows Details ------- http://vuln.sg/cybozugaroon-en.html http://vuln.sg/cybozugaroon-jp.html _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/