TT Web Site Manager 'index.php' SQL Injection Vulnerability
BID:42483
Info
TT Web Site Manager 'index.php' SQL Injection Vulnerability
| Bugtraq ID: | 42483 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4732 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2009 12:00AM |
| Updated: | Aug 04 2009 12:00AM |
| Credit: | SirGod |
| Vulnerable: |
John W. List TT Web Site Manager 0.5 |
| Not Vulnerable: | |
Discussion
TT Web Site Manager 'index.php' SQL Injection Vulnerability
TT Web Site Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TT Web Site Manager 0.5 is vulnerable; other versions may also be affected.
TT Web Site Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TT Web Site Manager 0.5 is vulnerable; other versions may also be affected.
Exploit / POC
TT Web Site Manager 'index.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
TT Web Site Manager 'index.php' SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TT Web Site Manager 'index.php' SQL Injection Vulnerability
References:
References:
- TT Web Site Manager Homepage (John W. List)