LBlog Comments.ASP SQL Injection Vulnerability
BID:19607
CVE-2006-4284 |Info
LBlog Comments.ASP SQL Injection Vulnerability
| Bugtraq ID: | 19607 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2006 12:00AM |
| Updated: | Oct 13 2006 08:14PM |
| Credit: | Chironex Fleckeri is credited with the discovery of this vulnerability. |
| Vulnerable: |
LBlog LBlog 1.05 |
| Not Vulnerable: |
LBlog LBlog 2.0 |
Discussion
LBlog Comments.ASP SQL Injection Vulnerability
LBlog is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
LBlog 1.05 and prior versions are affected by this issue.
LBlog is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
LBlog 1.05 and prior versions are affected by this issue.
Exploit / POC
LBlog Comments.ASP SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
A proof of concept is available:
Attackers can exploit this issue via a web client.
A proof of concept is available:
Solution / Fix
LBlog Comments.ASP SQL Injection Vulnerability
Solution:
The vendor has released version 2.0 to address this issue. Please see the advisories section for more information.
LBlog LBlog 1.05
Solution:
The vendor has released version 2.0 to address this issue. Please see the advisories section for more information.
LBlog LBlog 1.05
-
LBlog LBlog v.2.0
http://www.lblog.dk/download/LBlog-2.0.rar