RETIRED: W1L3D4 WEBmarket Urunbak.ASP SQL Injection Vulnerability
BID:24550
Info
RETIRED: W1L3D4 WEBmarket Urunbak.ASP SQL Injection Vulnerability
| Bugtraq ID: | 24550 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | Jun 20 2007 08:39AM |
| Credit: | Crackers_Child is credited with the discovery of this vulnerability. |
| Vulnerable: |
W1L3D4 WEBmarket 0.1 |
| Not Vulnerable: | |
Discussion
RETIRED: W1L3D4 WEBmarket Urunbak.ASP SQL Injection Vulnerability
WEBmarket is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
This issue affects version 0.1; other versions may also be affected.
WEBmarket is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
This issue affects version 0.1; other versions may also be affected.
Exploit / POC
RETIRED: W1L3D4 WEBmarket Urunbak.ASP SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/script_path/urunbak.asp?id=25+union+select+0,1,parola,3,4,5,6+from+ayar
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/script_path/urunbak.asp?id=25+union+select+0,1,parola,3,4,5,6+from+ayar
Solution / Fix
RETIRED: W1L3D4 WEBmarket Urunbak.ASP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
RETIRED: W1L3D4 WEBmarket Urunbak.ASP SQL Injection Vulnerability
References:
References: