TorrentTrader Classic Edition Multiple SQL Injection Vulnerabilities
BID:29787
Info
TorrentTrader Classic Edition Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 29787 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2428 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Secunia Research |
| Vulnerable: |
TorrentTrader TorrentTrader Classic Edition 1.08 |
| Not Vulnerable: | |
Discussion
TorrentTrader Classic Edition Multiple SQL Injection Vulnerabilities
TorrentTrader Classic Edition is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions of TorrentTrader 1.08 Classic Edition released before June 17, 2008 are vulnerable.
TorrentTrader Classic Edition is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions of TorrentTrader 1.08 Classic Edition released before June 17, 2008 are vulnerable.
Exploit / POC
TorrentTrader Classic Edition Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
TorrentTrader Classic Edition Multiple SQL Injection Vulnerabilities
Solution:
Versions of TorrentTrader 1.08 Classic Edition released after June 17, 2008 are not affected by these issues.
TorrentTrader TorrentTrader Classic Edition 1.08
Solution:
Versions of TorrentTrader 1.08 Classic Edition released after June 17, 2008 are not affected by these issues.
TorrentTrader TorrentTrader Classic Edition 1.08
-
TorrentTrader TorrentTraderClassic_v1.08.zip
http://downloads.sourceforge.net/torrenttrader/TorrentTraderClassic_v1 .08.zip?modtime=1213719753&big_mirror=0
References
TorrentTrader Classic Edition Multiple SQL Injection Vulnerabilities
References:
References:
- Release Name: FINAL v1.08 (TorrentTrader)
- TorrentTrader Homepage (TorrentTrader)
- Secunia Research: TorrentTrader Multiple SQL Injection Vulnerabilities (Secunia Research
) - TorrentTrader Multiple SQL Injection Vulnerabilities (Secunia)