Swinger Club Portal 'start.php' SQL Injection and Remote File Include Vulnerabilities
BID:43622
Info
Swinger Club Portal 'start.php' SQL Injection and Remote File Include Vulnerabilities
| Bugtraq ID: | 43622 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4751 CVE-2009-4752 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2009 12:00AM |
| Updated: | Jul 07 2009 12:00AM |
| Credit: | Moudi |
| Vulnerable: |
Phppool media group Swinger Club Portal 0 |
| Not Vulnerable: | |
Discussion
Swinger Club Portal 'start.php' SQL Injection and Remote File Include Vulnerabilities
Swinger Club Portal is prone to an SQL-injection vulnerability and a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to access or modify data, exploit latent vulnerabilities in the underlying database, obtain potentially sensitive information, or execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
Swinger Club Portal is prone to an SQL-injection vulnerability and a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to access or modify data, exploit latent vulnerabilities in the underlying database, obtain potentially sensitive information, or execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
Exploit / POC
Swinger Club Portal 'start.php' SQL Injection and Remote File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/anzeiger/start.php?go=rubrik&id=[SQL]
http://www.example.com/anzeiger/start.php?go=[RFI]
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/anzeiger/start.php?go=rubrik&id=[SQL]
http://www.example.com/anzeiger/start.php?go=[RFI]
Solution / Fix
Swinger Club Portal 'start.php' SQL Injection and Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Swinger Club Portal 'start.php' SQL Injection and Remote File Include Vulnerabilities
References:
References:
- Swinger Club Portal Product Page (phppool Media Group)