MKPortal Unspecified SQL Injection Vulnerability
BID:24783
Info
MKPortal Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 24783 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3637 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | WabiSabiLabi reported this issue. The researcher responsible for discovering this vulnerability is not known. |
| Vulnerable: |
MKPortal MKPortal 1.1.1 |
| Not Vulnerable: | |
Discussion
MKPortal Unspecified SQL Injection Vulnerability
MKPortal is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerability in the underlying database.
Few technical details are currently available. We will update this BID as more information emerges.
This issue affects MKPortal 1.1.1; other versions may also be vulnerable.
MKPortal is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in SQL queries.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerability in the underlying database.
Few technical details are currently available. We will update this BID as more information emerges.
This issue affects MKPortal 1.1.1; other versions may also be vulnerable.
Exploit / POC
MKPortal Unspecified SQL Injection Vulnerability
Attackers can exploit this issue via a browser.
A proof of concept has been developed but is not known to be publicly available.
Attackers can exploit this issue via a browser.
A proof of concept has been developed but is not known to be publicly available.
Solution / Fix
MKPortal Unspecified SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MKPortal Unspecified SQL Injection Vulnerability
References:
References:
- MKPortal Homepage (MKPortal)
- MKPortal SQL injection (WabiSabiLabi)