Release Date: 2009-01-02
Critical:
Highly critical
Impact: Manipulation of data
System access
Where: From remote
Solution Status: Vendor Patch
Software: CMScout 2.x
Description:
SirGod has discovered some vulnerabilities in CMScout, which can be exploited by malicious people and malicious users to conduct SQL injection attacks, and by malicious people to compromise a vulnerable system.
Solution:
Update to version 2.07.
Provided and/or discovered by:
SirGod
Original Advisory:
http://www.milw0rm.com/exploits/7625
FlexPHPic SQL Injection Vulnerabilities
Release Date: 2009-01-02
Critical:
Moderately critical
Impact: Security Bypass
Manipulation of data
Where: From remote
Solution Status: Unpatched
Software: FlexPHPic 0.x
Description:
S.W.A.T. has discovered some vulnerabilities in FlexPHPic, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "checkuser" and "checkpass" parameters in admin/index.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Successful exploitation allows bypassing the authentication mechanism, but requires that "magic_quotes_gpc" is disabled.
The vulnerabilities are confirmed in FlexPHPic 0.0.4 (English version) and FlexPHPic Pro 0.0.3 (English version). Other versions may also be affected.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
S.W.A.T.
Original Advisory:
http://www.milw0rm.com/exploits/7624

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic