Multiple WEBBDOMAIN Products Login Screen SQL Injection Vulnerability
BID:32108
Info
Multiple WEBBDOMAIN Products Login Screen SQL Injection Vulnerability
| Bugtraq ID: | 32108 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6623 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Hakxer and x0r |
| Vulnerable: |
WEBBDOMAIN WebShop 1.02 WEBBDOMAIN WebShop 1.01 WEBBDOMAIN Quiz 1.02 WEBBDOMAIN Quiz 1.0 WEBBDOMAIN post Card 1.02 WEBBDOMAIN post Card 1.01 WEBBDOMAIN Polls 1.0 WEBBDOMAIN Petition 3.0 WEBBDOMAIN Petition 2.0 WEBBDOMAIN Petition 1.0 |
| Not Vulnerable: | |
Discussion
Multiple WEBBDOMAIN Products Login Screen SQL Injection Vulnerability
Multiple WEBBDOMAIN products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
Quiz
WebShop
Polls
Petition
Post Card
Multiple WEBBDOMAIN products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
Quiz
WebShop
Polls
Petition
Post Card
Exploit / POC
Multiple WEBBDOMAIN Products Login Screen SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Supplying the following to the login screen is sufficient to exploit this issue:
Username : admin ' or ' 1=1
password : Hakxer
Attackers can use a browser to exploit this issue.
Supplying the following to the login screen is sufficient to exploit this issue:
Username : admin ' or ' 1=1
password : Hakxer
Solution / Fix
Multiple WEBBDOMAIN Products Login Screen SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple WEBBDOMAIN Products Login Screen SQL Injection Vulnerability
References:
References:
- Petition Homepage (WEBBDOMAIN)
- photo Card Homepage (WEBBDOMAIN)
- Polls Homepage (WEBBDOMAIN)
- Quiz Homepage (WEBBDOMAIN)
- WebShop Homepage (WEBBDOMAIN)