w3blabor CMS admin/index.php' SQL Injection Vulnerability
BID:33082
Info
w3blabor CMS admin/index.php' SQL Injection Vulnerability
| Bugtraq ID: | 33082 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 01 2009 12:00AM |
| Updated: | Jan 05 2009 05:42PM |
| Credit: | DNX |
| Vulnerable: |
w3blabor w3blabor 3.3 |
| Not Vulnerable: |
w3blabor w3blabor 3.4 |
Discussion
w3blabor CMS admin/index.php' SQL Injection Vulnerability
w3blabor CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
w3blabor CMS 3.3.0 and prior versions are vulnerable.
w3blabor CMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
w3blabor CMS 3.3.0 and prior versions are vulnerable.
Exploit / POC
w3blabor CMS admin/index.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example input is available:
Username: x' or 1=1/*
Password: not empty
Attackers can use a browser to exploit this issue.
The following example input is available:
Username: x' or 1=1/*
Password: not empty
Solution / Fix
w3blabor CMS admin/index.php' SQL Injection Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
w3blabor CMS admin/index.php' SQL Injection Vulnerability
References:
References:
- w3blabor CMS Homepage (w3blabor)