Retired: Kinesis Interactive Cinema System Index.ASP SQL Injection Vulnerability
BID:20607
Info
Retired: Kinesis Interactive Cinema System Index.ASP SQL Injection Vulnerability
| Bugtraq ID: | 20607 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5450 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Apr 05 2007 03:22AM |
| Credit: | fireboy is credited with the discovery of this vulnerability. |
| Vulnerable: |
Kinesis Kinesis Interactive Cinema System 0 |
| Not Vulnerable: | |
Discussion
Retired: Kinesis Interactive Cinema System Index.ASP SQL Injection Vulnerability
Kinesis Interactive Cinema System is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Since this is a site-specific issue, this BID is being retired.
Kinesis Interactive Cinema System is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Since this is a site-specific issue, this BID is being retired.
Exploit / POC
Retired: Kinesis Interactive Cinema System Index.ASP SQL Injection Vulnerability
An attacker can exploit this issue via a web client.
Supplying the following input to the 'index.asp' script is sufficient to exploit this issue:
user: 'or''='
pass: 'or''='
An attacker can exploit this issue via a web client.
Supplying the following input to the 'index.asp' script is sufficient to exploit this issue:
user: 'or''='
pass: 'or''='
Solution / Fix
Retired: Kinesis Interactive Cinema System Index.ASP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Retired: Kinesis Interactive Cinema System Index.ASP SQL Injection Vulnerability
References:
References:
- Vendor Homepage (Kinesis)