SOOP Portal Raven 'pm_show_message.asp' SQL Injection Vulnerability
BID:47664
Info
SOOP Portal Raven 'pm_show_message.asp' SQL Injection Vulnerability
| Bugtraq ID: | 47664 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2011 12:00AM |
| Updated: | Apr 29 2011 12:00AM |
| Credit: | Evil-Thinker |
| Vulnerable: |
SOOP Portal SOOP Portal Raven 1.0B |
| Not Vulnerable: | |
Discussion
SOOP Portal Raven 'pm_show_message.asp' SQL Injection Vulnerability
SOOP Portal Raven is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
SOOP Portal Raven 1.0b is vulnerable; other versions may also be affected.
SOOP Portal Raven is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
SOOP Portal Raven 1.0b is vulnerable; other versions may also be affected.
References
SOOP Portal Raven 'pm_show_message.asp' SQL Injection Vulnerability
References:
References:
- SOOP Portal Homepage (GeckoHeadlines)