phpBannerExchange Multiple SQL Injection Vulnerabilities
BID:18448
CVE-2006-3012 | CVE-2006-3013 |Info
phpBannerExchange Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 18448 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3013 CVE-2006-3012 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2006 12:00AM |
| Updated: | Jun 15 2006 09:41PM |
| Credit: | RedTeam Pentesting is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
eschew.net phpBannerExchange 2.0 RC5 eschew.net phpBannerExchange 2.0 |
| Not Vulnerable: |
eschew.net phpBannerExchange 2.0 RC6 |
Discussion
phpBannerExchange Multiple SQL Injection Vulnerabilities
phpBannerExchange is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
phpBannerExchange is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
phpBannerExchange Multiple SQL Injection Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
phpBannerExchange Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released version 2.0.RC5 to address these issues; please see the reference section for details.
eschew.net phpBannerExchange 2.0 RC5
eschew.net phpBannerExchange 2.0
Solution:
The vendor has released version 2.0.RC5 to address these issues; please see the reference section for details.
eschew.net phpBannerExchange 2.0 RC5
-
phpBannerExchange 2.0 RC6
http://www.eschew.net/scripts/download.php?id=12
eschew.net phpBannerExchange 2.0
-
phpBannerExchange 2.0 RC6
http://www.eschew.net/scripts/download.php?id=12
References
phpBannerExchange Multiple SQL Injection Vulnerabilities
References:
References:
- phpBannerExchange Homepage (eschew.net)
- phpBannerExchange SQL Vuln 1 (RedTeam Pentesting)
- phpBannerExchange SQL Vuln 2 (RedTeam Pentesting)
- Advisory: Unauthorized password recovery in phpBannerExchange (RedTeam Pentesting
) - RedTeam Pentesting
(Advisory: Authentication bypass in phpBannerExchange)