SQLproNews News Archives About Us Feedback
Web-Based Issue Tracking
Free 30-Day Trial - Click Here


Recent Articles

Microsoft SQL 2000 Disaster Recovery with SANRAD V-Switch - Planning Guide
Designing a disaster recovery system requires planning and consideration of the available options that will best fit your company's needs, SLA and budget.

MS SQL / MySQL - A Case Study

The release of Microsoft SQL Server 2005 on November 7th 2005 created a buzz around the office for IT professionals.

Taking Advantage of Open Source PHP MySQL Applications

One obvious solution is to approach a software development company and obtain a custom built product. However to take this approach one needs to first know what features and functionality is desired.

Programmer Overkill (MySQL)

I have a peeve about MySQL. Oh, not about MySQL directly: it's great. I love it, it's wonderful, no complaints. It's the people who use it when they don't need to that get me shaking my...

MySQL 5.0 Available For Production Use
MySQL AB announced the launch of MySQL 5.0 on Monday. The much-anticipated upgrade is available for download under the open source GPL license.



Write 10,000 lines of code in 10 minutes!
Iron Speed Designer – Free Evaluation
01.24.06


SQL Injection Vulnerability

By John Stith

A vulnerability was discovered in the ADOdb and can be exploited by hackers doing SQL injection attacks. The vulnerability only works on the PostgreSQL users. Andy Staudacher discovered the vulnerability and Secunia reported the issue as moderately critical on Tuesday.

The vulnerability itself showed up in previous version prior to the current 4.71 so the appropriate patchwork should be applied to all the previous version. The original release notes were posted at Sourceforge.net:

Recommended that all postgresql users upgrade to this version.
Fixes important postgresql security issues problems related
to binary strings. Thx to Andy Staudacher.

Also several DSN bugs fixed, including one introduced in 4.70
that corrupts underscores in the DSN, and in PHP5 DSN's did
not work. Added support for PDO DSN connections.


And the changes include:

DSN bugs found:

Web-Based Issue Tracking
Free 30-Day Trial - Click Here

1. Fix bugs in DSN connections introduced in 4.70 when
underscores are found in the DSN.

2. DSN with _ did not work properly in PHP5 (fine in PHP4). Fixed.

3. Added support for PDO DSN connections in
NewADOConnection(), and database parameter in PDO::Connect().

Other bugs:

The oci8 datetime flag not correctly implemented in ADORecordSet_array. Fixed.

Added BlobDelete() to postgres, as a counterpoint to UpdateBlobFile().

Fixed GetInsertSQL() to support oci8po.

Fixed qstr() issue with postgresql with \0 in strings.

Fixed some datadict driver loading issues in _adodb_getdriver().

Write 10,000 lines of code in 10 minutes!
Iron Speed Designer – Free Evaluation

Added register shutdown function session_write_close in adodb-session.inc.php for PHP 5 compat.


All this is in addition to other SQL injection vulnerabilities. On Monday, an injection vulnerability was found in Zoph. This one was rated as moderately critical and a vendor patch corrected the problem. This was also an injection vulnerability.

Secunia also discovered another SQL injection vulnerability in e-moBLOG. To exploit this, hackers must disable the "magic_quotes_gpc." While the vulnerability was confirmed in the 1.3 version, other versions could be affect also.

Input passed to the "monthy" parameter in index.php and the "login" parameter in admin/index.php is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

All these vulnerabilities showing up fairly close together suggests a little more editing might need to be done on these products. While they aren't all exactly the same, SQL was the key to each and all were injection vulnerabilities. In any event, make sure updates are maintained and this will help eliminate problems.


About the Author:
John Stith is a staff writer for WebProNews covering technology and business.

About SQLproNews
SQLproNews is a collection of up to date tutorials and insightful articles designed to help SQL users of any skill level implement successful SQL systems and practices. SQL Strategies and Tactics for Business

SQLproNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
SQLproNews.com WirelessProNews.com
CProgrammingTrends.com SysAdminNews.com




-- SQLProNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2006 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

advertising info | news headlines | free newsletters | comments/feedback | submit article



SQL Strategies and Tactics for Business SQLproNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact