Cosmoshop Multiple SQL Injection Vulnerabilities
BID:14689
Info
Cosmoshop Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 14689 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2005 12:00AM |
| Updated: | Aug 29 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Cosmoshop Cosmoshop 8.10 .78 |
| Not Vulnerable: | |
Discussion
Cosmoshop Multiple SQL Injection Vulnerabilities
Cosmoshop is prone to multiple SQL injection vulnerabilities. These issues are due to a lack of properly sanitized input to several CGI scipts.
An attacker may compromise this application by using SQL injection techniques to bypass the admin login process. Successful exploitation results in gaining full administrative access within the context of the affected application.
Cosmoshop is prone to multiple SQL injection vulnerabilities. These issues are due to a lack of properly sanitized input to several CGI scipts.
An attacker may compromise this application by using SQL injection techniques to bypass the admin login process. Successful exploitation results in gaining full administrative access within the context of the affected application.
Exploit / POC
Cosmoshop Multiple SQL Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Cosmoshop Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cosmoshop Multiple SQL Injection Vulnerabilities
References:
References: