Multiple ScriptMagix Products Index.PHP SQL Injection Vulnerability
BID:23015
Info
Multiple ScriptMagix Products Index.PHP SQL Injection Vulnerability
| Bugtraq ID: | 23015 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2007 12:00AM |
| Updated: | Mar 19 2007 07:04PM |
| Credit: | ajaan is credited with the discovery of this vulnerability. |
| Vulnerable: |
ScriptMagix Recipes 2.0 ScriptMagix Jokes 2.0 ScriptMagix FAQ Builder 2.0 |
| Not Vulnerable: | |
Discussion
Multiple ScriptMagix Products Index.PHP SQL Injection Vulnerability
Multiple ScriptMagix products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Multiple ScriptMagix products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Exploit / POC
Multiple ScriptMagix Products Index.PHP SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following sample exploits are available:
Attackers can use a browser to exploit this issue.
The following sample exploits are available:
Solution / Fix
Multiple ScriptMagix Products Index.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Multiple ScriptMagix Products Index.PHP SQL Injection Vulnerability
References:
References:
- ScriptMagix Homepage (ScriptMagix)