DGNews Search.PHP SQL Injection Vulnerability
BID:18887
Info
DGNews Search.PHP SQL Injection Vulnerability
| Bugtraq ID: | 18887 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2006 12:00AM |
| Updated: | Jul 11 2006 04:48PM |
| Credit: | NewAngels Team has been credited with the discovery of this vulnerability. |
| Vulnerable: |
Dian Gemilang DGNews 1.5.1 |
| Not Vulnerable: | |
Discussion
DGNews Search.PHP SQL Injection Vulnerability
DGNews is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
DGNews is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
DGNews Search.PHP SQL Injection Vulnerability
This issue can be exploited through a web-client.
The following proof-of-concept URI is available.
This issue can be exploited through a web-client.
The following proof-of-concept URI is available.
Solution / Fix
DGNews Search.PHP SQL Injection Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the referenced advisories for more information and fixes.
Solution:
The vendor has released an update to address this issue. Please see the referenced advisories for more information and fixes.
References
DGNews Search.PHP SQL Injection Vulnerability
References:
References:
- DGNews SQL Injection Vulnerability (DGNews)
- Dian Gemilang Home Page (Dian Gemilang )