SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
Link | Tags |
---|---|
http://www.osvdb.org/23462 | vdb entry |
http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt | vendor advisory exploit |
http://www.securityfocus.com/archive/1/425924/100/0/threaded | mailing list |
http://secunia.com/advisories/18993 | third party advisory |
http://www.vupen.com/english/advisories/2006/0718 | vdb entry |