GuestBookHost Multiple SQL Injection Vulnerabilities
BID:16545
Info
GuestBookHost Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 16545 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0542 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2006 12:00AM |
| Updated: | Feb 10 2006 09:18PM |
| Credit: | Aliaksandr Hartsuyeu is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
GuestBookHost GuestBookHost 2005.4.25 |
| Not Vulnerable: | |
Discussion
GuestBookHost Multiple SQL Injection Vulnerabilities
GuestBookHost is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 2005.04.25 is vulnerable; other versions may also be affected.
GuestBookHost is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 2005.04.25 is vulnerable; other versions may also be affected.
Exploit / POC
GuestBookHost Multiple SQL Injection Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
GuestBookHost Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
<mailto:[email protected]:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
<mailto:[email protected]:[email protected]>.
References
GuestBookHost Multiple SQL Injection Vulnerabilities
References:
References:
- GuestBookHost Authentication Bypass (eVuln.com)
- GuestBookHost Homepage (GuestBookHost)
- [eVuln] GuestBookHost Authentication Bypass ([email protected])