Ananda Real Estate List.ASP SQL Injection Vulnerability
BID:21771
Info
Ananda Real Estate List.ASP SQL Injection Vulnerability
| Bugtraq ID: | 21771 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-6807 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 26 2006 12:00AM |
| Updated: | Jun 17 2010 06:39PM |
| Credit: | ajann is credited with the discovery of this vulnerability. |
| Vulnerable: |
softwebsnepal Ananda Real Estate 3.4 |
| Not Vulnerable: | |
Discussion
Ananda Real Estate List.ASP SQL Injection Vulnerability
Ananda Real Estate is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Version 3.4 is vulnerable.
Ananda Real Estate is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Version 3.4 is vulnerable.
Exploit / POC
Solution / Fix
References
Ananda Real Estate List.ASP SQL Injection Vulnerability
References:
References:
- Real Estate Homepage (Softwebs Nepal)