|
|
Nuked-Klan "X-Forwarded-For" Header Processing Remote SQL Injection Vulnerability
|
A vulnerability has been identified in Nuked-Klan, which could be exploited by attackers to execute arbitrary SQL queries. This issue is caused by an input validation error when processing the "X-Forwarded-For" header, which could be exploited by malicious users to conduct SQL injection attacks and execute arbitrary code with the privileges of the web server.
Nuked-Klan version 1.7.6 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2007/1662
Vulnerability reported by DarkFig
2007-05-07 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|