Randshop Multiple SQL Injection Vulnerabilities
BID:15599
Info
Randshop Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 15599 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2005 12:00AM |
| Updated: | Jul 04 2006 09:04PM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Randshop Randshop |
| Not Vulnerable: |
Randshop Randshop 1.2 |
Discussion
Randshop Multiple SQL Injection Vulnerabilities
Randshop is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
All versions of Randshop are reported affected.
Randshop is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
All versions of Randshop are reported affected.
Exploit / POC
Randshop Multiple SQL Injection Vulnerabilities
This issue can be exploited through a web client.
Example URIs have been provided:
This issue can be exploited through a web client.
Example URIs have been provided:
Solution / Fix
Randshop Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released version 1.2 to address these issues; please see the reference section for details.
Solution:
The vendor has released version 1.2 to address these issues; please see the reference section for details.
References
Randshop Multiple SQL Injection Vulnerabilities
References:
References: