[Full-disclosure] [HTTPCS] FreeWebshop 'Text' Remote SQL Injection Vulnerability

2012-09-17 Thread HTTPCS
HTTPCS Advisory : HTTPCS100 Product : FreeWebshop Version : 2.2.9 Date : 2012-09-17 Criticality level : Highly Critical Description : A vulnerability has been discovered in FreeWebshop, which can be exploited by malicious people to conduct SQL injection attacks. Input passed via the 'Text'

Re: [Full-disclosure] [HTTPCS] FreeWebshop 'Text' Remote SQL Injection Vulnerability

2012-09-17 Thread Julius Kivimäki
Did you guys seriously just send five different advisories on five different vulnerable parameters on one vulnerable script? 2012/9/17 HTTPCS cont...@httpcs.com ** HTTPCS Advisory : HTTPCS100 Product : FreeWebshop Version : 2.2.9 Date : 2012-09-17 Criticality level : Highly Critical

Re: [Full-disclosure] [HTTPCS] FreeWebshop 'Text' Remote SQL Injection Vulnerability

2012-09-17 Thread Benji
you seem surprised by the level of idiocy, are you new to this list? On Mon, Sep 17, 2012 at 2:42 PM, Julius Kivimäki julius.kivim...@gmail.com wrote: Did you guys seriously just send five different advisories on five different vulnerable parameters on one vulnerable script? 2012/9/17 HTTPCS