TYPO3 Commerce Extension Unspecified SQL Injection Vulnerability
BID:32893
Info
TYPO3 Commerce Extension Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 32893 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5609 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2008 12:00AM |
| Updated: | Dec 19 2008 07:52PM |
| Credit: | Peter Athmann |
| Vulnerable: |
Typo3 Commerce 0.9.6 |
| Not Vulnerable: |
Typo3 Commerce 0.9.7 |
Discussion
TYPO3 Commerce Extension Unspecified SQL Injection Vulnerability
TYPO3 Commerce extension is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Commerce 0.9.7 are vulnerable.
TYPO3 Commerce extension is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Commerce 0.9.7 are vulnerable.
Exploit / POC
TYPO3 Commerce Extension Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
TYPO3 Commerce Extension Unspecified SQL Injection Vulnerability
Solution:
The vendor released an update and an advisory. Please see the references for more information.
Typo3 Commerce 0.9.6
Solution:
The vendor released an update and an advisory. Please see the references for more information.
Typo3 Commerce 0.9.6
-
Typo3 commerce_0.9.7.t3x
http://typo3.org/fileadmin/ter/c/o/commerce_0.9.7.t3x
References
TYPO3 Commerce Extension Unspecified SQL Injection Vulnerability
References:
References: