Point Market 'id' Parameter SQL Injection Vulnerability
BID:47288
Info
Point Market 'id' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 47288 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2011 12:00AM |
| Updated: | Apr 10 2011 12:00AM |
| Credit: | Net.Edit0r |
| Vulnerable: |
VBulletin Point Market System 3.1 |
| Not Vulnerable: | |
Discussion
Point Market 'id' Parameter SQL Injection Vulnerability
Point Market is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Point Market 3.1.0 is vulnerable; other versions may also be affected.
Point Market is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Point Market 3.1.0 is vulnerable; other versions may also be affected.
References
Point Market 'id' Parameter SQL Injection Vulnerability
References:
References:
- Point Market System Homepage (vBulletin)