Re: SQL injection vulnerability in boastMachine

2010-06-15 Thread security curmudgeon
Discovered 2008-01-21, covered by CVE-2008-0422 / OSVDB 40960. On Sat, 5 Jun 2010, advis...@htbridge.ch wrote: : Vulnerability ID: HTB22398 : Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_boastmachine.html : Product: boastMachine : Vendor: Kailash Nadh : Vulnerable V

SQL injection vulnerability in boastMachine

2010-06-07 Thread advisory
Vulnerability ID: HTB22398 Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_boastmachine.html Product: boastMachine Vendor: Kailash Nadh Vulnerable Version: 3.1 and Probably Prior Versions Vendor Notification: 20 May 2010 Vulnerability Type: SQL Injection Status: Not Fixe