SPIP Multiple SQL Injection Vulnerabilities
BID:16458
Info
SPIP Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 16458 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2006 12:00AM |
| Updated: | Feb 07 2006 08:56PM |
| Credit: | Siegfried and netcraft are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SPIP SPIP 1.9.Alpha 2 SPIP SPIP 1.9.Alpha 1 SPIP SPIP 1.8.2-e SPIP SPIP 1.8.2-d |
| Not Vulnerable: |
SPIP SPIP 1.8.2-f |
Discussion
SPIP Multiple SQL Injection Vulnerabilities
SPIP is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions prior to and including 1.8.2-e and 1.9 alpha 2 are vulnerable; other versions may also be affected.
SPIP is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Versions prior to and including 1.8.2-e and 1.9 alpha 2 are vulnerable; other versions may also be affected.
Exploit / POC
SPIP Multiple SQL Injection Vulnerabilities
An exploit is not required.
Example URIs have been provided:
http://wwww.example.com/forum.php3?id_article=1&id_forum=-1/**/UNION/**/SELECT%20pass%20from%20spip_auteurs/*
http://wwww.example.com/forum.php3?id_article=-1/**/UNION/**/SELECT%20pass%20from%20spip_auteurs/*
An exploit is not required.
Example URIs have been provided:
http://wwww.example.com/forum.php3?id_article=1&id_forum=-1/**/UNION/**/SELECT%20pass%20from%20spip_auteurs/*
http://wwww.example.com/forum.php3?id_article=-1/**/UNION/**/SELECT%20pass%20from%20spip_auteurs/*
Solution / Fix
SPIP Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
SPIP SPIP 1.9.Alpha 2
SPIP SPIP 1.8.2-e
SPIP SPIP 1.9.Alpha 1
SPIP SPIP 1.8.2-d
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
SPIP SPIP 1.9.Alpha 2
-
SPIP SPIP
spip.zip
http://trac.rezo.net/files/spip/spip.zip
SPIP SPIP 1.8.2-e
-
SPIP SPIP
spip.zip
http://trac.rezo.net/files/spip/spip.zip
SPIP SPIP 1.9.Alpha 1
-
SPIP SPIP
spip.zip
http://trac.rezo.net/files/spip/spip.zip
SPIP SPIP 1.8.2-d
-
SPIP SPIP
spip.zip
http://trac.rezo.net/files/spip/spip.zip
References
SPIP Multiple SQL Injection Vulnerabilities
References:
References: