Blog:CMS Multiple SQL Injection Vulnerabilities
BID:18839
Info
Blog:CMS Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 18839 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Jul 06 2006 04:39PM |
| Credit: | Ellipsis Security is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
BLOG:CMS BLOG:CMS 4.1 |
| Not Vulnerable: | |
Discussion
Blog:CMS Multiple SQL Injection Vulnerabilities
Blog:CMS is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Version 4.1.0 is vulnerable; other versions may also be affected.
Blog:CMS is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Version 4.1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Blog:CMS Multiple SQL Injection Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
Blog:CMS Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Blog:CMS Multiple SQL Injection Vulnerabilities
References:
References:
- BLOG:CMS Sql Injection (hackers.ir)
- Blog:CMS Web Site (Blog:CMS)