ilchClan 'statistic.php' SQL Injection Vulnerability
BID:33678
Info
ilchClan 'statistic.php' SQL Injection Vulnerability
| Bugtraq ID: | 33678 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2009 12:00AM |
| Updated: | Feb 11 2009 06:18PM |
| Credit: | Gizmore, wechall.net |
| Vulnerable: |
ilch.de ilchClan 1.1L |
| Not Vulnerable: |
ilch.de ilchClan 1.1M |
Discussion
ilchClan 'statistic.php' SQL Injection Vulnerability
ilchClan is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ilchClan 1.1L is vulnerable; other versions may be affected as well.
ilchClan is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ilchClan 1.1L is vulnerable; other versions may be affected as well.
Exploit / POC
ilchClan 'statistic.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
ilchClan 'statistic.php' SQL Injection Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
ilchClan 'statistic.php' SQL Injection Vulnerability
References:
References:
- Security Fix | Update M (ilch.de)
- Vendor Homepage (Ilch)