Release date: 2011-12-19
Updated on:
Affected Systems:
MnoGoSearch 3.x
Unaffected system:
MnoGoSearch 3.3.12
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51113
Cve id: CVE-2011-5235
MnoGoSearch is a search engine software.
The SQL injection vulnerability exists in versions earlier than mnoGoSearch 3.3.12. The host name in the hypertext connection allows attackers to control applications, access or modify data, and exploit other vulnerabilities in the underlying database.
<* Source: vendor
Link: http://secunia.com/advisories/47272
Http://www.mnogosearch.org/doc33/msearch-changelog.html#changelog-3-3-12
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MnoGoSearch
-----------
MnoGoSearch has released a Security Bulletin (changelog-3-3-12) and patches for this:
Changelog-3-3-12: Appendix A. mnoGoSearch change history
Link: http://www.mnogosearch.org/doc33/msearch-changelog.html#changelog-3-3-12