VP-ASP Shopproductselect.ASP SQL Injection Vulnerability
BID:14305
Info
VP-ASP Shopproductselect.ASP SQL Injection Vulnerability
| Bugtraq ID: | 14305 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 18 2005 12:00AM |
| Credit: | The vendor has reported this issue. |
| Vulnerable: |
Virtual Programming VP-ASP 5.00 Virtual Programming VP-ASP 4.50 Virtual Programming VP-ASP 4.00 Virtual Programming VP-ASP 3.00 |
| Not Vulnerable: | |
Discussion
VP-ASP Shopproductselect.ASP SQL Injection Vulnerability
It is confirmed that the VP-ASP Shopping Cart is prone to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
It is possible for an attacker to disclose the user password hashes, or other sensitive information contained within the database by exploiting this issue.There is also the possibility of exploiting latent vulnerabilities in the underlying database implementation.
It is confirmed that the VP-ASP Shopping Cart is prone to a remote SQL injection vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it in an SQL query.
It is possible for an attacker to disclose the user password hashes, or other sensitive information contained within the database by exploiting this issue.There is also the possibility of exploiting latent vulnerabilities in the underlying database implementation.
Exploit / POC
VP-ASP Shopproductselect.ASP SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
VP-ASP Shopproductselect.ASP SQL Injection Vulnerability
Solution:
The vendor has acknowledged this vulnerability and has released a workaround.
An upgrade is not yet available.
Solution:
The vendor has acknowledged this vulnerability and has released a workaround.
An upgrade is not yet available.
References
VP-ASP Shopproductselect.ASP SQL Injection Vulnerability
References:
References:
- VP-ASP Homepage (Virtual Programming )
- VP-ASP Security FAQ (Virtual Programming)