XOOPS Multiple Modules ViewCat.PHP SQL Injection Vulnerabilities
BID:23229
Info
XOOPS Multiple Modules ViewCat.PHP SQL Injection Vulnerabilities
| Bugtraq ID: | 23229 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2007 12:00AM |
| Updated: | Apr 06 2007 03:22AM |
| Credit: | ajann is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Xoops myAlbum-P 2.0 Xoops Module Tutoriais 0 Xoops Module Library 0 Xoops Module Core 0 |
| Not Vulnerable: | |
Discussion
XOOPS Multiple Modules ViewCat.PHP SQL Injection Vulnerabilities
Multiple XOOPS Modules are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Multiple XOOPS Modules are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
Exploit / POC
XOOPS Multiple Modules ViewCat.PHP SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploits are available:
Attackers can use a browser to exploit these issues.
The following exploits are available:
Solution / Fix
XOOPS Multiple Modules ViewCat.PHP SQL Injection Vulnerabilities
Solution:
The vendor has reportedly addressed this issue in a new version. Please contact the vendor for information on how to obtain and apply the new version.
Solution:
The vendor has reportedly addressed this issue in a new version. Please contact the vendor for information on how to obtain and apply the new version.
References
XOOPS Multiple Modules ViewCat.PHP SQL Injection Vulnerabilities
References:
References:
- XOOP Module Repository Homepage (XOOP)
- XOOPS Homepage (XOOPS)