ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
BID:16406
Info
ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 16406 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4334 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2005 12:00AM |
| Updated: | Apr 12 2006 09:12PM |
| Credit: | Tran Viet Phuong is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Zixforum Zixforum 1.12 |
| Not Vulnerable: | |
Discussion
ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
ZixForum is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
ZixForum is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
An exploit is not required.
The following proof-of-concept URI is available:
http://www.example.com/forum/forum.asp?pageid=1&H_ID=9 [ SQL INJEC]
An exploit is not required.
The following proof-of-concept URI is available:
http://www.example.com/forum/forum.asp?pageid=1&H_ID=9 [ SQL INJEC]
Solution / Fix
ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released a fix to address this issue; please contact the vendor for further information.
Solution:
The vendor has released a fix to address this issue; please contact the vendor for further information.
References
ZixForum Forum.ASP Multiple SQL Injection Vulnerabilities
References:
References:
- Zixforum Product Page (Zixforum)