XIGLA SOFTWARE Absolute Banner Manager .NET SQL Injection Vulnerability
BID:26754
Info
XIGLA SOFTWARE Absolute Banner Manager .NET SQL Injection Vulnerability
| Bugtraq ID: | 26754 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6291 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2007 12:00AM |
| Updated: | Dec 18 2007 01:51PM |
| Credit: | Joseph Pierini is credited with the discovery of this vulnerability. |
| Vulnerable: |
XIGLA SOFTWARE Absolute Banner Manager .NET 4.0 |
| Not Vulnerable: | |
Discussion
XIGLA SOFTWARE Absolute Banner Manager .NET SQL Injection Vulnerability
Absolute Banner Manager .NET is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Absolute Banner Manager .NET 4.0 is reported vulnerable; other versions may be affected as well.
Absolute Banner Manager .NET is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Absolute Banner Manager .NET 4.0 is reported vulnerable; other versions may be affected as well.
Exploit / POC
XIGLA SOFTWARE Absolute Banner Manager .NET SQL Injection Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
XIGLA SOFTWARE Absolute Banner Manager .NET SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
XIGLA SOFTWARE Absolute Banner Manager .NET SQL Injection Vulnerability
References:
References:
- Absolute Banner Manager .NET 4.0 (XIGLA SOFTWARE)