Retired: SpireMedia CMS Index.cfm SQL Injection Vulnerability
BID:16039
Info
Retired: SpireMedia CMS Index.cfm SQL Injection Vulnerability
| Bugtraq ID: | 16039 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2005 12:00AM |
| Updated: | Jan 18 2006 06:25PM |
| Credit: | Discovered by rakstija r0t3d3Vil. |
| Vulnerable: |
SpireMedia SpireMedia CMS mx7 |
| Not Vulnerable: | |
Discussion
Retired: SpireMedia CMS Index.cfm SQL Injection Vulnerability
SpireMedia CMS is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
SpireMedia CMS mx7 is prone to this issue. Other versions may also be affected.
Vendor information is available stating SpireMedia is not affected by this issue. Therefore this BID is being retired.
SpireMedia CMS is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
SpireMedia CMS mx7 is prone to this issue. Other versions may also be affected.
Vendor information is available stating SpireMedia is not affected by this issue. Therefore this BID is being retired.
Exploit / POC
Retired: SpireMedia CMS Index.cfm SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Retired: SpireMedia CMS Index.cfm SQL Injection Vulnerability
Solution:
Vendor information is available stating SpireMedia is not affected by this issue. Therefore this BID is being retired.
Solution:
Vendor information is available stating SpireMedia is not affected by this issue. Therefore this BID is being retired.
References
Retired: SpireMedia CMS Index.cfm SQL Injection Vulnerability
References:
References:
- SpireMedia CMS SQL inj. vuln. (rakstija r0t3d3Vil)
- SpireMedia Home Page (SpireMedia)