New User, Welcome!     Login

Re: SQL injection vulnerability in WebDB

From: security curmudgeon <jericho attrition org>
To: advisory htbridge ch
Cc: bugtraq securityfocus com
Subject: Re: SQL injection vulnerability in WebDB
Date: Mon - Jul 05, 2010 11:55 AM



Hello,

For both of your WebDB advisories, you say:

: Product: WebDB
: Vendor: Lois Software
: Vulnerable Version: 2.0a and Probably Prior Versions

: Status: Fixed by Vendor
: Risk level: High 

: Solution: There is no need for anybody to upgrade to the latest version. 

Why is there no need for anybody to upgrade to the latest version on a 
"High risk" vulnerability? 

In addition, could you please include vendor URLs in all of your 
advisories?

Thanks




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!