Fantastic Scripts Fantastic News SQL Injection Vulnerability
BID:16842
Info
Fantastic Scripts Fantastic News SQL Injection Vulnerability
| Bugtraq ID: | 16842 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2006 12:00AM |
| Updated: | Mar 01 2006 05:16AM |
| Credit: | Discovered by SAUDI. |
| Vulnerable: |
Fantastic Scripts Fantastic News 2.1.1 |
| Not Vulnerable: | |
Discussion
Fantastic Scripts Fantastic News SQL Injection Vulnerability
Fantastic News is prone to an SQL-injection vulnerability.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Fantastic News 2.1.1 is affected.
Fantastic News is prone to an SQL-injection vulnerability.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Fantastic News 2.1.1 is affected.
Exploit / POC
Fantastic Scripts Fantastic News SQL Injection Vulnerability
This issue may be exploited through a web browser
The following proof of concept is available:
http://www.example.com/news.php?page=|sql
This issue may be exploited through a web browser
The following proof of concept is available:
http://www.example.com/news.php?page=|sql
Solution / Fix
Fantastic Scripts Fantastic News SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Fantastic Scripts Fantastic News SQL Injection Vulnerability
References:
References:
- Fantastic News Product Page (Fantastic Scripts)
- 2 SQL Injection in Fantastic News ([email protected])