SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field).
Link | Tags |
---|---|
http://retrogod.altervista.org/JAWS_062_sql.html | exploit |
http://secunia.com/advisories/20842 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27334 | vdb entry |
http://www.jaws-project.com/index.php?blog/show/29 | patch |
http://securityreason.com/securityalert/1165 | third party advisory |
http://www.securityfocus.com/archive/1/438434/100/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2006/2546 | vdb entry |
http://www.securityfocus.com/bid/18665 | vdb entry exploit |