Multiple BrotherScripts 'username' and 'password' SQL Injection Vulnerabilities
BID:41371
Info
Multiple BrotherScripts 'username' and 'password' SQL Injection Vulnerabilities
| Bugtraq ID: | 41371 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2010 12:00AM |
| Updated: | Jul 06 2010 05:58PM |
| Credit: | Sid3^effects |
| Vulnerable: |
BrotherScripts Scripts Directory 0 BrotherScripts Recipe Website 0 BrotherScripts Business Directory 0 BrotherScripts Auction Software 0 |
| Not Vulnerable: | |
Discussion
Multiple BrotherScripts 'username' and 'password' SQL Injection Vulnerabilities
Multiple BrotherScripts applications are prone to multiple SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following are affected:
Scripts Directory
Recipe Website
Business Directory
Auction Software
Multiple BrotherScripts applications are prone to multiple SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following are affected:
Scripts Directory
Recipe Website
Business Directory
Auction Software
Exploit / POC
Multiple BrotherScripts 'username' and 'password' SQL Injection Vulnerabilities
Attackers can use a browser to exploit this issue.
Supplying the following to the username or password fields is sufficient to exploit this issue:
' or 1=1 or ''='
Attackers can use a browser to exploit this issue.
Supplying the following to the username or password fields is sufficient to exploit this issue:
' or 1=1 or ''='
Solution / Fix
Multiple BrotherScripts 'username' and 'password' SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple BrotherScripts 'username' and 'password' SQL Injection Vulnerabilities
References:
References:
- BrotherScripts Homepage (BrotherScripts)