Description
The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.
References (5)
Core 5
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/09/05/5
Product x_refsource_confirm
http://sourceforge.net/projects/smbind/files/smbind/0.4.8/smbind-0.4.8.tar.bz2/download
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2010/dsa-2103
Exploit x_refsource_misc
http://packetstormsecurity.org/1009-exploits/smbind-sql.txt
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/09/07/10
Scores
EPSS
0.0188
EPSS Percentile
77.2%
Details
CWE
CWE-89
Status
published
Products (11)
blentz/smbind
0.2
blentz/smbind
0.2.1
blentz/smbind
0.3.1
blentz/smbind
0.4
blentz/smbind
0.4.1
blentz/smbind
0.4.2
blentz/smbind
0.4.3
blentz/smbind
0.4.4
blentz/smbind
0.4.5
blentz/smbind
0.4.6
... and 1 more
Published
Oct 14, 2010
Tracked Since
Feb 18, 2026