Mall23 Infopage.ASP SQL Injection Vulnerability
BID:14803
Info
Mall23 Infopage.ASP SQL Injection Vulnerability
| Bugtraq ID: | 14803 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2005 12:00AM |
| Updated: | Sep 12 2005 12:00AM |
| Credit: | This vulnerability was discovered by David Sopas Ferreira. |
| Vulnerable: |
Mall23 Mall23 |
| Not Vulnerable: | |
Discussion
Mall23 Infopage.ASP SQL Injection Vulnerability
Mall23 is prone to an SQL injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Mall23 is prone to an SQL injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Mall23 Infopage.ASP SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Mall23 Infopage.ASP SQL Injection Vulnerability
Solution:
The vendor has released a patch addressing this issue. Symantec recommends users contact the vendor for details about obtaining and applying the appropriate patch.
Solution:
The vendor has released a patch addressing this issue. Symantec recommends users contact the vendor for details about obtaining and applying the appropriate patch.
References
Mall23 Infopage.ASP SQL Injection Vulnerability
References:
References:
- Mall23 Web Site (Mall23)
- SS#10092005 - Mall23 SQL Injection (David Sopas Ferreira)