w3b|cms Multiple SQL Injection Vulnerabilities
BID:33706
Info
w3b|cms Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 33706 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2009 12:00AM |
| Updated: | Feb 11 2009 07:08PM |
| Credit: | DNX |
| Vulnerable: |
w3bcms w3b|cms 3.5 w3bcms Suche module 1.5 w3bcms Sitemap module 1.5 w3bcms Portfolio module 2.0 w3bcms Partner module 1.5 w3bcms News module 1.5 w3bcms Mediathek module 1.5 w3bcms Links module 1.5 w3bcms Gallery module 1.5 w3bcms Downloads module 1.5 w3bcms Blog module 1.5 |
| Not Vulnerable: |
w3bcms w3b|cms 3.5.1 |
Discussion
w3b|cms Multiple SQL Injection Vulnerabilities
The 'w3b|cms' program is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affected the following:
w3b|cms 3.5.0 and prior
Downloads module 1.5.0
News module 1.5.0
Portfolio module 2.0.0
Partner module 1.5.0
Mediathek module 1.5.0
Sitemap module 1.5.0
Links module 1.5.0
Blog module 1.5.0
Suche module 1.5.0
Gallery module 1.5.0
The 'w3b|cms' program is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affected the following:
w3b|cms 3.5.0 and prior
Downloads module 1.5.0
News module 1.5.0
Portfolio module 2.0.0
Partner module 1.5.0
Mediathek module 1.5.0
Sitemap module 1.5.0
Links module 1.5.0
Blog module 1.5.0
Suche module 1.5.0
Gallery module 1.5.0
Exploit / POC
w3b|cms Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploit code is available:
Attackers can use a browser to exploit these issues.
The following exploit code is available:
Solution / Fix
w3b|cms Multiple SQL Injection Vulnerabilities
Solution:
Reportedly, the vendor has released fixes, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has released fixes, but Symantec has not confirmed this. Please contact the vendor for more information.