Release Date: 2008-11-06
Critical:
Less critical
Impact: Security Bypass
Where: Local system
Solution Status: Vendor Patch
OS: Debian GNU/Linux 4.0
Description:
Debian has issued an update for mysql-dfsg-5.0. This fixes a security issue, which can be exploited by malicious, local users to bypass certain security restrictions.
Solution:
Apply updated packages.
Original Advisory:
DSA-1662-1:
http://lists.debian.org/debian-security-announce/2008/msg00254.html
Other References:
SA30134:
http://secunia.com/advisories/30134/
Five Dollar Scripts Drinks Script "recid" SQL Injection Vulnerability
Release Date: 2008-11-06
Critical:
Moderately critical
Impact: Manipulation of data
Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Software: Five Dollar Scripts Drinks Script
Description:
Ex Tacy has reported a vulnerability in Five Dollar Scripts Drinks script, which can be exploited by malicious people to conduct SQL injection attacks.
Input passed to the "recid" parameter in index.php (when "cmd" is set to "6") is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Solution:
Edit the source code to ensure that input is properly sanitised.
Provided and/or discovered by:
Ex Tacy
Original Advisory:
http://milw0rm.com/exploits/7007

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic