Arab Portal Link.PHP SQL Injection Vulnerabilities
BID:15820
Info
Arab Portal Link.PHP SQL Injection Vulnerabilities
| Bugtraq ID: | 15820 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2005 12:00AM |
| Updated: | Dec 12 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Arab Portal System Arab Portal System 2.0 beta 2 |
| Not Vulnerable: | |
Discussion
Arab Portal Link.PHP SQL Injection Vulnerabilities
Arab Portal is prone to multiple SQL injection vulnerabilities. These are due to a lack of proper sanitization of user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Arab Portal is prone to multiple SQL injection vulnerabilities. These are due to a lack of proper sanitization of user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Arab Portal Link.PHP SQL Injection Vulnerabilities
No exploit is required.
An example URI has been provided:
http://www.example.com/Arab_Portal_v.2.0_beta_2/link.php?action=list&cat_id=5&',
'010','Hacker','0')/*
No exploit is required.
An example URI has been provided:
http://www.example.com/Arab_Portal_v.2.0_beta_2/link.php?action=list&cat_id=5&',
'010','Hacker','0')/*
Solution / Fix
Arab Portal Link.PHP SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Arab Portal Link.PHP SQL Injection Vulnerabilities
References:
References:
- Arab Portal Homepage (Arab Portal)
- Arab Portal v2 Beta2 SQL Injections ([email protected])