CMS MUNDO Control Panel SQL Injection Vulnerability
BID:18451
CVE-2006-2911 |Info
CMS MUNDO Control Panel SQL Injection Vulnerability
| Bugtraq ID: | 18451 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2911 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2006 12:00AM |
| Updated: | Jun 20 2006 07:40PM |
| Credit: | Adreas Sandblad of Secunia Research is credited with this discovery of this vulnerability. |
| Vulnerable: |
hotwebscripts CMS Mundo 1.0 build 007 hotwebscripts CMS Mundo 1.0 |
| Not Vulnerable: |
hotwebscripts CMS Mundo 1.0 build 008 |
Discussion
CMS MUNDO Control Panel SQL Injection Vulnerability
CMS Mundo is prone an SQL injection vulnerability.
An attacker can gain administrative access to the application through exploiting this vulnerability. Other attacks are also possible, depending on the nature of the affected query and the underlying database implementation.
CMS Mundo is prone an SQL injection vulnerability.
An attacker can gain administrative access to the application through exploiting this vulnerability. Other attacks are also possible, depending on the nature of the affected query and the underlying database implementation.
Exploit / POC
CMS MUNDO Control Panel SQL Injection Vulnerability
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
CMS MUNDO Control Panel SQL Injection Vulnerability
Solution:
The vendor has released version 1.0 build 008 to address this issue.
Solution:
The vendor has released version 1.0 build 008 to address this issue.
References
CMS MUNDO Control Panel SQL Injection Vulnerability
References:
References:
- CMS Mundo (hotwebscripts)
- CMS Mundo SQL Injection and File Upload Vulnerabilities (Secunia Research)