T.G.S. CMS Logout.PHP SQL Injection Vulnerability
BID:20850
Info
T.G.S. CMS Logout.PHP SQL Injection Vulnerability
| Bugtraq ID: | 20850 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2006 12:00AM |
| Updated: | Nov 14 2006 05:31PM |
| Credit: | Kacper is credited with the discovery of this vulnerability. |
| Vulnerable: |
T.G.S. T.G.S. CMS 0.1.7 |
| Not Vulnerable: | |
Discussion
T.G.S. CMS Logout.PHP SQL Injection Vulnerability
T.G.S. CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
T.G.S. CMS 0.1.7 and prior versions are vulnerable.
T.G.S. CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
T.G.S. CMS 0.1.7 and prior versions are vulnerable.
Exploit / POC
T.G.S. CMS Logout.PHP SQL Injection Vulnerability
An attacker can exploit this issue via a web client.
The following exploit code is available:
An attacker can exploit this issue via a web client.
The following exploit code is available:
Solution / Fix
T.G.S. CMS Logout.PHP SQL Injection Vulnerability
Solution:
The vendor has released a patch to address this issue.
T.G.S. T.G.S. CMS 0.1.7
Solution:
The vendor has released a patch to address this issue.
T.G.S. T.G.S. CMS 0.1.7
References
T.G.S. CMS Logout.PHP SQL Injection Vulnerability
References:
References:
- Remote SQL Injection Exploit (T.G.S.)
- T.G.S. Homepage (T.G.S.)