Web Wiz Forum Search.ASP SQL Injection Vulnerability
BID:20778
Info
Web Wiz Forum Search.ASP SQL Injection Vulnerability
| Bugtraq ID: | 20778 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2006 12:00AM |
| Updated: | Nov 08 2006 09:41PM |
| Credit: | aLMaSTeR is credited with the discovery of this vulnerability. |
| Vulnerable: |
Web Wiz Forums Web Wiz Forums 7.91 Web Wiz Forums Web Wiz Forums 7.51 Web Wiz Forums Web Wiz Forums 7.9 Web Wiz Forums Web Wiz Forums 7.8 Web Wiz Forums Web Wiz Forums 7.7 b Web Wiz Forums Web Wiz Forums 7.7 a Web Wiz Forums Web Wiz Forums 7.5 Web Wiz Forums Web Wiz Forums 7.0 beta1 Web Wiz Forums Web Wiz Forums 7.0 1 Web Wiz Forums Web Wiz Forums 7.0 Web Wiz Forums Web Wiz Forums 6.34 |
| Not Vulnerable: |
Web Wiz Forums Web Wiz Forums 7.94 |
Discussion
Web Wiz Forum Search.ASP SQL Injection Vulnerability
Web Wiz Forum is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Web Wiz Forum is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Web Wiz Forum Search.ASP SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/forum/search.asp?KW=|SQL|
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/forum/search.asp?KW=|SQL|
Solution / Fix
Web Wiz Forum Search.ASP SQL Injection Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for further information.
Solution:
The vendor has released an update to address this issue. Please see the references for further information.