360 Web Manager 'webpages-form-led-edit.php' SQL Injection Vulnerability
BID:40378
Info
360 Web Manager 'webpages-form-led-edit.php' SQL Injection Vulnerability
| Bugtraq ID: | 40378 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2010 12:00AM |
| Updated: | May 24 2010 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
360 Web Manager 360 Web Manager 3.0 |
| Not Vulnerable: | |
Discussion
360 Web Manager 'webpages-form-led-edit.php' SQL Injection Vulnerability
360 Web Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
360 Web Manager 3.0 is vulnerable; other versions may also be affected.
360 Web Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
360 Web Manager 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
360 Web Manager 'webpages-form-led-edit.php' SQL Injection Vulnerability
An attacker can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/adm/content/webpages/webpages-form-led-edit.php?IDFM=-1+ANY_SQL_HERE+--+
An attacker can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/adm/content/webpages/webpages-form-led-edit.php?IDFM=-1+ANY_SQL_HERE+--+
Solution / Fix
360 Web Manager 'webpages-form-led-edit.php' SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
360 Web Manager 'webpages-form-led-edit.php' SQL Injection Vulnerability
References:
References:
- 360 Web Manager Homepage (360 Web Manager)
- SQL injection vulnerability in 360 Web Manager ([email protected])