Article Publisher Pro 'admin.php' SQL Injection Vulnerability
BID:32030
Info
Article Publisher Pro 'admin.php' SQL Injection Vulnerability
| Bugtraq ID: | 32030 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4901 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Hakxer |
| Vulnerable: |
scriptsfrenzy.com Article Publisher Pro 1.5 |
| Not Vulnerable: | |
Discussion
Article Publisher Pro 'admin.php' SQL Injection Vulnerability
Article Publisher Pro is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Article Publisher Pro 1.5 is vulnerable; other versions may also be affected.
Article Publisher Pro is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Article Publisher Pro 1.5 is vulnerable; other versions may also be affected.
Exploit / POC
Article Publisher Pro 'admin.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example is available:
In Username Write : admin ' or ' 1=1
In Password Write any thing Example : Hakxer
Click Login ..! Now You Are In admin panel
Attackers can use a browser to exploit this issue.
The following example is available:
In Username Write : admin ' or ' 1=1
In Password Write any thing Example : Hakxer
Click Login ..! Now You Are In admin panel
Solution / Fix
Article Publisher Pro 'admin.php' SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Article Publisher Pro 'admin.php' SQL Injection Vulnerability
References:
References:
- Article Publisher Pro Homepage (scriptsfrenzy.com)