CMS Froggs Rejestracja.PHP SQL Injection Vulnerability
BID:19727
CVE-2006-4536 |Info
CMS Froggs Rejestracja.PHP SQL Injection Vulnerability
| Bugtraq ID: | 19727 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2006 12:00AM |
| Updated: | Aug 31 2006 08:08PM |
| Credit: | Kacper has been credited with the discovery of this vulnerability. |
| Vulnerable: |
CMS frogss CMS frogss 0.4 |
| Not Vulnerable: | |
Discussion
CMS Froggs Rejestracja.PHP SQL Injection Vulnerability
CMS Froggs is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well, including administrative access to the application.
CMS Froggs 0.4 and prior versions are reported vulnerable.
CMS Froggs is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit this issue to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well, including administrative access to the application.
CMS Froggs 0.4 and prior versions are reported vulnerable.
Exploit / POC
CMS Froggs Rejestracja.PHP SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
CMS Froggs Rejestracja.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
CMS Froggs Rejestracja.PHP SQL Injection Vulnerability
References:
References:
- CMS Frogss Home Page (CMS Frogss)