VBZooM Multiple SQL Injection Vulnerabilitie
BID:18937
CVE-2006-3691 |Info
VBZooM Multiple SQL Injection Vulnerabilitie
| Bugtraq ID: | 18937 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3691 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Jul 03 2007 07:18PM |
| Credit: | C.B.B.L is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
VBZoom VBZoom 1.11 |
| Not Vulnerable: | |
Discussion
VBZooM Multiple SQL Injection Vulnerabilitie
VBZooM is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
VBZooM is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Exploit / POC
VBZooM Multiple SQL Injection Vulnerabilitie
Attackers may exploit these issues through a browser.
Attackers may exploit these issues through a browser.
Solution / Fix
VBZooM Multiple SQL Injection Vulnerabilitie
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
VBZooM Multiple SQL Injection Vulnerabilitie
References:
References:
- VBZooM Homepage (VBZooM)
- SQL Injection In Script VBZooM V1.12 (Hasadya Raed)
- VBZooM 'sendmail.php' SQL Injection (C.B.B.L)
- VBZooM <=V1.11 'ignore-pm.php' SQL Injection (C.B.B.L)
- VBZooM <=V1.11 'reply.php' SQL Injection (C.B.B.L)
- VBZooM <=V1.11 'sub-join.php' SQL Injection (C.B.B.L)