phpWebSite 'links.php' SQL Injection Vulnerability
BID:32011
Info
phpWebSite 'links.php' SQL Injection Vulnerability
| Bugtraq ID: | 32011 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6266 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Beenu Arora |
| Vulnerable: |
phpWebsite phpWebsite 0.9.3 -4 phpWebsite phpWebsite 0.9.3 -3 phpWebsite phpWebsite 0.9.3 -2 phpWebsite phpWebsite 0.9.3 -1 phpWebsite phpWebsite 0.9.3 phpWebsite phpWebsite 0.8.3 phpWebsite phpWebsite 0.8.2 phpWebsite phpWebsite 0.7.3 |
| Not Vulnerable: | |
Discussion
phpWebSite 'links.php' SQL Injection Vulnerability
phpWebSite is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
We don't know which versions of phpWebSite are affected. We will update this BID as more information emerges.
NOTE: The vendor refutes this issue, stating that the vulnerable script has not been present in the application since either the 0.8.x or 0.9.x releases.
phpWebSite is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
We don't know which versions of phpWebSite are affected. We will update this BID as more information emerges.
NOTE: The vendor refutes this issue, stating that the vulnerable script has not been present in the application since either the 0.8.x or 0.9.x releases.
Exploit / POC
phpWebSite 'links.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/links.php?op=viewlink&cid=5+and+1=2+union+select+concat(version(),0x3a,database(),0x3a,user())--
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/links.php?op=viewlink&cid=5+and+1=2+union+select+concat(version(),0x3a,database(),0x3a,user())--
Solution / Fix
phpWebSite 'links.php' SQL Injection Vulnerability
Solution:
NOTE: The vendor refutes this issue, stating that the vulnerable script has not been present in the application since either the 0.8.x or 0.9.x releases.
Solution:
NOTE: The vendor refutes this issue, stating that the vulnerable script has not been present in the application since either the 0.8.x or 0.9.x releases.
References
phpWebSite 'links.php' SQL Injection Vulnerability
References:
References: