PowerPortal Remote SQL Injection Vulnerability
BID:11681
Info
PowerPortal Remote SQL Injection Vulnerability
| Bugtraq ID: | 11681 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2004 12:00AM |
| Updated: | Nov 14 2004 12:00AM |
| Credit: | Discovery is credited to ruggine <[email protected].>. |
| Vulnerable: |
PowerPortal PowerPortal 1.3 |
| Not Vulnerable: | |
Discussion
PowerPortal Remote SQL Injection Vulnerability
PowerPortal is reported vulnerable to remote SQL injection. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.
PowerPortal 1.3 is reported prone to this vulnerability, however, it is possible that other versions are affected as well.
PowerPortal is reported vulnerable to remote SQL injection. This issue is due to a failure of the application to properly validate user-supplied input prior to including it in an SQL query.
PowerPortal 1.3 is reported prone to this vulnerability, however, it is possible that other versions are affected as well.
Exploit / POC
PowerPortal Remote SQL Injection Vulnerability
An example URI sufficient to exploit this vulnerability has been provided:
http://www.example.com/pp13/index.php?index_page=and 1=1
An example URI sufficient to exploit this vulnerability has been provided:
http://www.example.com/pp13/index.php?index_page=and 1=1
Solution / Fix
PowerPortal Remote SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.