Cactusoft Parodia 'ag_id' Parameter SQL Injection Vulnerability
BID:48458
Info
Cactusoft Parodia 'ag_id' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 48458 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2011 12:00AM |
| Updated: | Jun 26 2012 02:00PM |
| Credit: | Carlos Mario Penagos Hollmann of Synapse Information Technology. |
| Vulnerable: |
CactuSoft Parodia 6.8 CactuSoft Parodia 6.4 CactuSoft Parodia 6.2 |
| Not Vulnerable: |
CactuSoft Parodia 6.809 |
Discussion
Cactusoft Parodia 'ag_id' Parameter SQL Injection Vulnerability
Parodia is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Parodia 6.8 and prior versions are vulnerable.
Parodia is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Parodia 6.8 and prior versions are vulnerable.
Exploit / POC
Cactusoft Parodia 'ag_id' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/agencyprofile.asp?AG_ID='
http://www.example.com/employer-profile.asp?ag_id='
Attackers can use a browser to exploit this issue.
The following example URIs are available:
http://www.example.com/agencyprofile.asp?AG_ID='
http://www.example.com/employer-profile.asp?ag_id='
Solution / Fix
Cactusoft Parodia 'ag_id' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please contact the vendor for more information.
Solution:
Updates are available. Please contact the vendor for more information.
References
Cactusoft Parodia 'ag_id' Parameter SQL Injection Vulnerability
References:
References:
- Parodia Homepage (CactuSoft)
- Parodia blind SQL injection vulnerability (CERT)