RETIRED: Newsletter Manager Plus.Attach 'admin/index.asp' Multiple SQL Injection Vulnerabilities
BID:33919
Info
RETIRED: Newsletter Manager Plus.Attach 'admin/index.asp' Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 33919 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2009 12:00AM |
| Updated: | Feb 27 2009 05:27PM |
| Credit: | ByALBAYX |
| Vulnerable: |
DesignerFreeSolutions Newsletter Manager Plus.Attach 5.40 |
| Not Vulnerable: | |
Discussion
RETIRED: Newsletter Manager Plus.Attach 'admin/index.asp' Multiple SQL Injection Vulnerabilities
Newsletter Manager Plus.Attach is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Newsletter Manager Plus.Attach 5.40 is vulnerable; other versions may also be affected.
UPDATE (February 27, 2009): The vendor reports that this issue affects only the demo version of the application. This BID is being retired.
Newsletter Manager Plus.Attach is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Newsletter Manager Plus.Attach 5.40 is vulnerable; other versions may also be affected.
UPDATE (February 27, 2009): The vendor reports that this issue affects only the demo version of the application. This BID is being retired.
Exploit / POC
RETIRED: Newsletter Manager Plus.Attach 'admin/index.asp' Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example data is available:
Username : ' or '
Password : ' or '
Attackers can use a browser to exploit these issues.
The following example data is available:
Username : ' or '
Password : ' or '
Solution / Fix
RETIRED: Newsletter Manager Plus.Attach 'admin/index.asp' Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Update (Feb. 27, 2009): The vendor reports that this issue only affects the demo version of the application. This BID is being retired.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Update (Feb. 27, 2009): The vendor reports that this issue only affects the demo version of the application. This BID is being retired.
References
RETIRED: Newsletter Manager Plus.Attach 'admin/index.asp' Multiple SQL Injection Vulnerabilities
References:
References:
- Newsletter Manager Plus.Attach Homepage (DesignerFreeSolutions)