Datavore Gyro SQL Injection and Cross Site Scripting Vulnerabilities
BID:42862
Info
Datavore Gyro SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 42862 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3348 CVE-2009-3349 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2009 12:00AM |
| Updated: | Sep 11 2009 12:00AM |
| Credit: | OoN_Boy |
| Vulnerable: |
Datavore Gyro 5.0 |
| Not Vulnerable: | |
Discussion
Datavore Gyro SQL Injection and Cross Site Scripting Vulnerabilities
Datavore Gyro is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Datavore Gyro 5.0 is vulnerable, other versions may also be affected.
Datavore Gyro is prone to an SQL-injection vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Datavore Gyro 5.0 is vulnerable, other versions may also be affected.
Exploit / POC
Datavore Gyro SQL Injection and Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URI is available:
SQL Injection:
1) http://www.example.com/home?op=cat&cid=29+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14--
Attackers can use a browser to exploit these issues.
The following example URI is available:
SQL Injection:
1) http://www.example.com/home?op=cat&cid=29+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14--
Solution / Fix
Datavore Gyro SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Datavore Gyro SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- Gyro - Homepage (Datavore)