Sux Services is prone to SQL injection attacks. In some cases, data supplied by IRC clients may not be adequately sanitized before being included in queries to the underlying database. This issue was due to an insecure implementation of a printf() related function which was used to print queries to the database. Exploitation may allow for modification of SQL queries, resulting in information disclosure, database corruption or other attacks.
Sux Services is prone to SQL injection attacks. In some cases, data supplied by IRC clients may not be adequately sanitized before being included in queries to the underlying database. This issue was due to an insecure implementation of a printf() related function which was used to print queries to the database. Exploitation may allow for modification of SQL queries, resulting in information disclosure, database corruption or other attacks.