Fantastic Scripts Fantastic News News.PHP SQL Injection Vulnerability
BID:15622
Info
Fantastic Scripts Fantastic News News.PHP SQL Injection Vulnerability
| Bugtraq ID: | 15622 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2005 12:00AM |
| Updated: | Nov 29 2005 12:00AM |
| Credit: | Discovered by rakstija r0t3d3Vil. |
| Vulnerable: |
Fantastic Scripts Fantastic News 2.1.1 |
| Not Vulnerable: | |
Discussion
Fantastic Scripts Fantastic News News.PHP SQL Injection Vulnerability
Fantastic News is prone to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Fantastic News 2.1.1 and prior versions are affected.
Fantastic News is prone to an SQL injection vulnerability.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Fantastic News 2.1.1 and prior versions are affected.
Exploit / POC
Fantastic Scripts Fantastic News News.PHP SQL Injection Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com/news.php?action=news&category=[SQL]
No exploit is required.
The following proof of concept is available:
http://www.example.com/news.php?action=news&category=[SQL]
Solution / Fix
Fantastic Scripts Fantastic News News.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Fantastic Scripts Fantastic News News.PHP SQL Injection Vulnerability
References:
References:
- Fantastic News "category" SQL inj. (rakstija r0t3d3Vil)
- Fantastic News Product Page (Fantastic Scripts)