Counter Strike Portals 'download' SQL Injection Vulnerability
BID:27747
Info
Counter Strike Portals 'download' SQL Injection Vulnerability
| Bugtraq ID: | 27747 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0733 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | S@BUN is credited with the discovery of this vulnerability. |
| Vulnerable: |
CS Team Counter Strike Portal 0 |
| Not Vulnerable: | |
Discussion
Counter Strike Portals 'download' SQL Injection Vulnerability
Counter Strike Portals is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Counter Strike Portals is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Solution / Fix
References
Counter Strike Portals 'download' SQL Injection Vulnerability
References:
References: