Blog:CMS Pitem Multiple SQL Injection Vulnerabilities
BID:19909
CVE-2006-4748 |Info
Blog:CMS Pitem Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 19909 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2006 12:00AM |
| Updated: | Sep 08 2006 07:12PM |
| Credit: | Omid is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
BLOG:CMS BLOG:CMS 4.1 |
| Not Vulnerable: |
BLOG:CMS BLOG:CMS 4.1.1 |
Discussion
Blog:CMS Pitem Multiple SQL Injection Vulnerabilities
Blog:CMS is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Version 4.1.0 is vulnerable; other versions may also be affected.
Blog:CMS is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker may be able to exploit these issues to modify the logic of SQL queries. Successful exploits may allow the attacker to compromise the software, retrieve information, or modify data; other consequences are possible as well.
Version 4.1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Blog:CMS Pitem Multiple SQL Injection Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
Blog:CMS Pitem Multiple SQL Injection Vulnerabilities
Solution:
An update is available to address these vulnerabilities. Please see the references for more information.
Solution:
An update is available to address these vulnerabilities. Please see the references for more information.
References
Blog:CMS Pitem Multiple SQL Injection Vulnerabilities
References:
References:
- BLOG:CMS Sql Injection (hackers.ir)
- Blog:CMS Web Site (Blog:CMS)