CVE-2010-3076

The filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:blentz:smbind:*:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4.4:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4.3:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4.6:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.4.5:*:*:*:*:*:*:*
cpe:2.3:a:blentz:smbind:0.2:*:*:*:*:*:*:*

Information

Published : 2010-10-13 22:57

Updated : 2011-01-18 22:59


NVD link : CVE-2010-3076

Mitre link : CVE-2010-3076


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

blentz

  • smbind