DZOIC Handshakes 'fname' Parameter SQL Injection Vulnerability
BID:29353
Info
DZOIC Handshakes 'fname' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 29353 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2781 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | s3rv3r_hack3r(Ali Jasbi) |
| Vulnerable: |
DZOIC Handshakes 3.5 |
| Not Vulnerable: | |
Discussion
DZOIC Handshakes 'fname' Parameter SQL Injection Vulnerability
DZOIC Handshakes is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
DZOIC Handshakes 3.5 is vulnerable; other versions may also be affected.
DZOIC Handshakes is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
DZOIC Handshakes 3.5 is vulnerable; other versions may also be affected.
Exploit / POC
DZOIC Handshakes 'fname' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example exploit is available:
http://www.example.com/dzoic/index.php?handler=search&action=perform&search_type=members&fname=[Sql Injection]&lname=jakson&[email protected]&handshakes=0&distance=0&country=0&state=0&city=0&postal_code=12345&online=on&with_photo=on&submit=Search
Attackers can use a browser to exploit this issue.
The following example exploit is available:
http://www.example.com/dzoic/index.php?handler=search&action=perform&search_type=members&fname=[Sql Injection]&lname=jakson&[email protected]&handshakes=0&distance=0&country=0&state=0&city=0&postal_code=12345&online=on&with_photo=on&submit=Search
Solution / Fix
DZOIC Handshakes 'fname' Parameter SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
DZOIC Handshakes 'fname' Parameter SQL Injection Vulnerability
References:
References: