CVE-2010-3076

NameCVE-2010-3076
DescriptionThe filter function in php/src/include.php in Simple Management for BIND (aka smbind) before 0.4.8 does not anchor a certain regular expression, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via the username parameter to the admin login page.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2103-1

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
smbindsourcelenny0.4.7-3+lenny1DSA-2103-1
smbindsource(unstable)0.4.7-5high

Notes

http://packetstormsecurity.org/1009-exploits/smbind-sql.txt

Search for package or bug name: Reporting problems