TurnkeyForms Web Hosting Directory Login SQL Injection Vulnerability
BID:36166
Info
TurnkeyForms Web Hosting Directory Login SQL Injection Vulnerability
| Bugtraq ID: | 36166 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6941 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2008 12:00AM |
| Updated: | Aug 27 2009 05:32PM |
| Credit: | G4N0K |
| Vulnerable: |
TurnkeyForms Web Hosting Directory 0 |
| Not Vulnerable: | |
Discussion
TurnkeyForms Web Hosting Directory Login SQL Injection Vulnerability
TurnkeyForms Web Hosting Directory is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TurnkeyForms Web Hosting Directory is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
TurnkeyForms Web Hosting Directory Login SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example data is available:
Username: [a valid username]
Password:' or '1=1
Attackers can use a browser to exploit this issue.
The following example data is available:
Username: [a valid username]
Password:' or '1=1
Solution / Fix
TurnkeyForms Web Hosting Directory Login SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TurnkeyForms Web Hosting Directory Login SQL Injection Vulnerability
References:
References:
- Web Hosting Directory Homepage (TurnkeyForms)