20040729 Jaws 0.4: authentication bypassmailing list
http://marc.info/?l=bugtraq&m=109116345930380&w=2 CVE-2004-2067
Jaws 0.2/0.3/0.4 - 'ControlPanel.php' SQL Injection
Record summary
CVE-2004-2067 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJaws 0.2/0.3/0.4 - 'ControlPanel.php' SQL InjectionExploitDB exploitby Fernando QuinteroNot analyzed1 file
References
71010815vdb entry
http://securitytracker.com/id?1010815 jaws.com.mxConfirmation
http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10 8320vdb entry
http://www.osvdb.org/8320 10826vdb entry
http://www.securityfocus.com/bid/10826 jaws-controlpanel-sql-injection(16847)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16847 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2067