IlchClan Multiple SQL Injection Vulnerabilities
BID:16735
Info
IlchClan Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 16735 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2006 12:00AM |
| Updated: | Feb 23 2006 03:52PM |
| Credit: | Discovered by x128 - alexander wilhelm. |
| Vulnerable: |
ilch.de ilchClan 1.0.5 G ilch.de ilchClan 1.0.5 F |
| Not Vulnerable: | |
Discussion
IlchClan Multiple SQL Injection Vulnerabilities
The 'ilchClan' program is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
An attacker may exploit these issues to gain access as an arbitrary user.
The 'ilchClan' program is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
An attacker may exploit these issues to gain access as an arbitrary user.
Exploit / POC
IlchClan Multiple SQL Injection Vulnerabilities
An exploit is not required.
The following proof of concepts are available:
http://www.example.com/index.php?m=forum&um=newpost&tid=1&pid=0[sql]
http://www.securityfocus.com/data/vulnerabilities/exploits/ilchclan_poc
An exploit is not required.
The following proof of concepts are available:
http://www.example.com/index.php?m=forum&um=newpost&tid=1&pid=0[sql]
http://www.securityfocus.com/data/vulnerabilities/exploits/ilchclan_poc
Solution / Fix
IlchClan Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]