Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
BID:16789
Info
Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
| Bugtraq ID: | 16789 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2006 12:00AM |
| Updated: | Feb 24 2006 06:02PM |
| Credit: | ReZEN is credited with the discovery of this vulnerability. |
| Vulnerable: |
MitriDAT Limited Web Calendar Pro 0 |
| Not Vulnerable: | |
Discussion
Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
Web Calendar Pro is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. Exploitation may also cause a denial-of-service condition.
Web Calendar Pro is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. Exploitation may also cause a denial-of-service condition.
Exploit / POC
Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
This issue can be exploited through a web client.
An example URI has been provided:
http://www.example.com/pathtocalendar/dropbase.php?tabls=' or 1=1 --
This issue can be exploited through a web client.
An example URI has been provided:
http://www.example.com/pathtocalendar/dropbase.php?tabls=' or 1=1 --
Solution / Fix
Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
References
Web Calendar Pro Dropbase.PHP SQL Injection Vulnerability
References:
References:
- Web Calendar Pro - Denial of Service SQL injection (lame) (XOR Crew)
- Web Calendar Pro Web Site (MitriDAT)