AspReady FAQ Manager SQL Injection Vulnerability
BID:15022
Info
AspReady FAQ Manager SQL Injection Vulnerability
| Bugtraq ID: | 15022 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2005 12:00AM |
| Updated: | Oct 06 2005 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
aspReady FAQ Manager aspReady FAQ Manager |
| Not Vulnerable: | |
Discussion
AspReady FAQ Manager SQL Injection Vulnerability
aspReady FAQ Manager is prone to an SQL injection vulnerability.
It is conjectured that various parameters and fields are affected by SQL injection attacks, however, this was not confirmed. Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. Reportedly, an attacker can exploit this issue to gain administrative access to a forum.
All versions of the application are considered to be vulnerable at the moment.
Specific details about this issue were not disclosed, however, this BID will be updated when more information becomes available.
aspReady FAQ Manager is prone to an SQL injection vulnerability.
It is conjectured that various parameters and fields are affected by SQL injection attacks, however, this was not confirmed. Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. Reportedly, an attacker can exploit this issue to gain administrative access to a forum.
All versions of the application are considered to be vulnerable at the moment.
Specific details about this issue were not disclosed, however, this BID will be updated when more information becomes available.
Exploit / POC
AspReady FAQ Manager SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
AspReady FAQ Manager SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AspReady FAQ Manager SQL Injection Vulnerability
References:
References:
- Product Page (aspReady FAQ Manager)
- aspReady FAQ - open for SQL-injections ([email protected])