Agares Media Arcadem Pro 'index.php' SQL Injection Vulnerability
BID:36069
Info
Agares Media Arcadem Pro 'index.php' SQL Injection Vulnerability
| Bugtraq ID: | 36069 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2009 12:00AM |
| Updated: | Aug 28 2009 05:22PM |
| Credit: | Mr.SQL |
| Vulnerable: |
Agares Media Arcadem Pro 2.0 |
| Not Vulnerable: |
Agares Media Arcadem Pro 2.900 |
Discussion
Agares Media Arcadem Pro 'index.php' SQL Injection Vulnerability
Arcadem Pro is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Arcadem Pro 2.0 is vulnerable; other versions may also be affected.
Arcadem Pro is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Arcadem Pro 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Agares Media Arcadem Pro 'index.php' SQL Injection Vulnerability
Attackers can exploit this issue via a browser.
The following exploit is available:
Attackers can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
Agares Media Arcadem Pro 'index.php' SQL Injection Vulnerability
Solution:
Arcadem Pro 2.900 and later are not affected by this issue. Please contact the vendor to obtain fixes.
Solution:
Arcadem Pro 2.900 and later are not affected by this issue. Please contact the vendor to obtain fixes.
References
Agares Media Arcadem Pro 'index.php' SQL Injection Vulnerability
References:
References:
- Arcadem Pro Homepage (Agares Media)