Ultimate Regnow Affiliate 'rss.php' SQL Injection Vulnerability
BID:43373
Info
Ultimate Regnow Affiliate 'rss.php' SQL Injection Vulnerability
| Bugtraq ID: | 43373 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2009 12:00AM |
| Updated: | Jul 28 2009 12:00AM |
| Credit: | Chip D3 Bi0s |
| Vulnerable: |
PHPSugar Ultimate Regnow Affiliate 3.0 |
| Not Vulnerable: | |
Discussion
Ultimate Regnow Affiliate 'rss.php' SQL Injection Vulnerability
Ultimate Regnow Affiliate is prone to a SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in a SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Ultimate Regnow Affiliate 3.0 is vulnerable; other versions may also be affected.
Ultimate Regnow Affiliate is prone to a SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in a SQL query.
Exploiting this issue could allow an attacker to execute arbitrary code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Ultimate Regnow Affiliate 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Ultimate Regnow Affiliate 'rss.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
References
Ultimate Regnow Affiliate 'rss.php' SQL Injection Vulnerability
References:
References:
- Ultimate Regnow Affiliate Homepage (phpSUGAR)