|
06/26/2004
26/06/2004 ZH2004-10SA (security advisory): Sql Injection in Help Desp Pro 2.0 Discovered: June 1st 2004 Vendor contacted: June 1st 2004 Title: Help Desk Pro Vulnerable versions :2.0 unpatched Type: Sql Injection Author: D'Amato Luigi from Zone-h Security Labs - [EMAIL PROTECTED] - [EMAIL PROTECTED] Vendor: http://www.websoft.it/
Description ********** Detail ******************************************** Due to an improper login validation in the login page it is possible to bypass the authentication mechanism Solution ********** The vendor has been contacted and has released a patch
D'Amato Luigi from Zone-h Security Labs - |
