New eVuln Advisory: BirthSys SQL Injection Vulnerability http://evuln.com/vulns/74/summary.html --------------------Summary---------------- eVuln ID: EV0074 CVE: CVE-2006-0775 Software: BirthSys Sowtware's Web Site: http://clvfoto.free.fr/site/download.php3 Versions: 3.1 Critical Level: Moderate Type: SQL Injection Class: Remote Status: Unpatched. No reply from developer(s) Exploit: Available Solution: Not Available Discovered by: Aliaksandr Hartsuyeu (eVuln.com) -----------------Description--------------- Vulnerable script: show.php Variables $month $date are not properly sanitized. This can be used to make any SQL query by injecting arbitrary SQL code. --------------Exploit---------------------- Available at: http://evuln.com/vulns/74/exploit.html SQL Injection Example. http://host/show.php3? month=99%20union% 20select%201, 2,3,4,5/* --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu (eVuln.com) Regards, Aliaksandr Hartsuyeu http://evuln.com - Penetration Testing Services .