Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
BID:15199
Info
Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
| Bugtraq ID: | 15199 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3325 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2005 12:00AM |
| Updated: | Oct 25 2005 12:00AM |
| Credit: | Remco Verhoef is credited with the discovery of this vulnerability. |
| Vulnerable: |
Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 BASE Basic Analysis and Security Engine 1.2 ACID Acidlab 0.9.6 |
| Not Vulnerable: |
BASE Basic Analysis and Security Engine 1.2.1 |
Discussion
Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
Basic Analysis And Security Engine is prone to an SQL injection vulnerability.
This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Basic Analysis And Security Engine is prone to an SQL injection vulnerability.
This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
No exploit is required.
An example URI has been provided:
http://www.example.com/base/base_qry_main.php?new=1&sig[0]=%3D&sig[1]=[SQL]&submit=Query+DB
No exploit is required.
An example URI has been provided:
http://www.example.com/base/base_qry_main.php?new=1&sig[0]=%3D&sig[1]=[SQL]&submit=Query+DB
Solution / Fix
Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
Solution:
Debian has released advisory DSA 893-1 and fixes to address this issue. Please see the referenced advisory for further information.
The vendor has released Basic Analysis and Security Engine version 1.2.1 to address this issue.
ACID Acidlab 0.9.6
BASE Basic Analysis and Security Engine 1.2
Solution:
Debian has released advisory DSA 893-1 and fixes to address this issue. Please see the referenced advisory for further information.
The vendor has released Basic Analysis and Security Engine version 1.2.1 to address this issue.
ACID Acidlab 0.9.6
-
Debian acidlab-doc_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab-doc_0.9 .6b20-10.1_all.deb -
Debian acidlab-mysql_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab-mysql_0 .9.6b20-10.1_all.deb -
Debian acidlab-pgsql_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab-pgsql_0 .9.6b20-10.1_all.deb -
Debian acidlab_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab_0.9.6b2 0-10.1_all.deb -
Debian acidlab_0.9.6b20-2.1_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/acidlab/acidlab_0.9.6b2 0-2.1_all.deb
BASE Basic Analysis and Security Engine 1.2
-
BASE base-1.2.1.tar.gz
http://prdownloads.sourceforge.net/secureideas/base-1.2.1.tar.gz?downl oad
References
Basic Analysis And Security Engine Base_qry_main.PHP SQL Injection Vulnerability
References:
References: