Multiple MyioSoft Products Login Screen SQL Injection Vulnerability
BID:32199
Info
Multiple MyioSoft Products Login Screen SQL Injection Vulnerability
| Bugtraq ID: | 32199 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5652 CVE-2008-5653 CVE-2008-5654 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2008 12:00AM |
| Updated: | Dec 18 2008 11:41PM |
| Credit: | ZoRLu |
| Vulnerable: |
MyioSoft EasyCalendar 4.0tr MyioSoft EasyBookMarker 4.0tr MyioSoft Ajax Portal 3.0 |
| Not Vulnerable: | |
Discussion
Multiple MyioSoft Products Login Screen SQL Injection Vulnerability
Multiple MyioSoft products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
Ajax Portal 3.0
EasyBookMarker
EasyCalendar
Other products and versions may also be affected.
Multiple MyioSoft products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
Ajax Portal 3.0
EasyBookMarker
EasyCalendar
Other products and versions may also be affected.
Exploit / POC
Multiple MyioSoft Products Login Screen SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Supplying the following to the login screen is sufficient to exploit this issue:
username : admin ' or ' 1=1
password : ZoRLu
Attackers can use a browser to exploit this issue.
Supplying the following to the login screen is sufficient to exploit this issue:
username : admin ' or ' 1=1
password : ZoRLu
Solution / Fix
Multiple MyioSoft Products Login Screen SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple MyioSoft Products Login Screen SQL Injection Vulnerability
References:
References:
- Vendor Homepage (MyioSoft)