20020415 Demarc PureSecure 1.05 may be other (user can bypass login)mailing list
http://archives.neohapsis.com/archives/bugtraq/2002-04/0168.html CVE-2002-0539
Demarc PureSecure 1.0.5 - Authentication Check SQL Injection
Record summary
CVE-2002-0539 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDemarc PureSecure 1.0.5 - Authentication Check SQL InjectionExploitDB exploitby pokleyzz sakamaniakaNot analyzed1 file
References
620020417 Demarc Security Update Advisorymailing list
http://online.securityfocus.com/archive/1/267941 puresecure-sql-injection(8854)vdb entry
http://www.iss.net/security_center/static/8854.php 5239vdb entry
http://www.osvdb.org/5239 4520vdb entry
http://www.securityfocus.com/bid/4520 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0539