AEwebworks aeDating Search_Result.PHP SQL Injection Vulnerability
BID:14847
Info
AEwebworks aeDating Search_Result.PHP SQL Injection Vulnerability
| Bugtraq ID: | 14847 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2005 12:00AM |
| Updated: | Sep 15 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
AEwebworks Dating Software aeDating 4.0 AEwebworks Dating Software aeDating 3.2 |
| Not Vulnerable: | |
Discussion
AEwebworks aeDating Search_Result.PHP SQL Injection Vulnerability
AEwebworks aeDating is prone to an SQL injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before it is used in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
AEwebworks aeDating is prone to an SQL injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before it is used in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
AEwebworks aeDating Search_Result.PHP SQL Injection Vulnerability
No exploit is required.
An example has been provided:
http://www.example.com/search_result.php?Sex=male&LookingFor=female&DateOfBirth_start=18&DateOfBirth_end=40&Country%5B%5D=0UNION
No exploit is required.
An example has been provided:
http://www.example.com/search_result.php?Sex=male&LookingFor=female&DateOfBirth_start=18&DateOfBirth_end=40&Country%5B%5D=0UNION
Solution / Fix
AEwebworks aeDating Search_Result.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AEwebworks aeDating Search_Result.PHP SQL Injection Vulnerability
References:
References:
- aeDating Product Page (AEwebworks Dating Software)