WEB//NEWS Multiple SQL Injection Vulnerabilities
BID:31776
Info
WEB//NEWS Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 31776 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2008 12:00AM |
| Updated: | Oct 17 2008 07:07PM |
| Credit: | David Vieira-Kurz |
| Vulnerable: |
Stylemotion WEB//NEWS 1.4 |
| Not Vulnerable: |
Stylemotion WEB//NEWS 1.4.1a |
Discussion
WEB//NEWS Multiple SQL Injection Vulnerabilities
WEB//NEWS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to WEB//NEWS 1.4.1a are vulnerable.
WEB//NEWS is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to WEB//NEWS 1.4.1a are vulnerable.
Exploit / POC
WEB//NEWS Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
WEB//NEWS Multiple SQL Injection Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
WEB//NEWS Multiple SQL Injection Vulnerabilities
References:
References: