Multiple DMXReady Products 'ItemId' Parameter SQL Injection Vulnerability
BID:48543
Info
Multiple DMXReady Products 'ItemId' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 48543 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2011 12:00AM |
| Updated: | Jul 06 2011 07:50AM |
| Credit: | Bellatrix |
| Vulnerable: |
DMXReady Secure Document Library 1.2 DMXReady News Manager 1.2 DMXReady Faq Manager 1.2 DMXReady Document Library Manager 1.2 DMXReady Contact Us Manager 1.2 DMXReady Bilboard 1.2 |
| Not Vulnerable: | |
Discussion
Multiple DMXReady Products 'ItemId' Parameter SQL Injection Vulnerability
Multiple DMXReady products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
News Manager
Contact Us Manage
Faqs Manager
Bilboard
Document Library Manager
Secure Document Library
Multiple DMXReady products are prone to an SQL-injection vulnerability because they fail to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
News Manager
Contact Us Manage
Faqs Manager
Bilboard
Document Library Manager
Secure Document Library
Exploit / POC
Multiple DMXReady Products 'ItemId' Parameter SQL Injection Vulnerability
An attacker can use a browser to exploit this issue.
The following example URIs is available:
http://www.example.com/path/admin/NewsManager/update.asp?ItemID=[SQL ATTACK]
http://www.example.com/path/admin/SecureDocumentLibrary/DocumentLibraryManager/update.asp?ItemID=xx[SQL ATTACK]
An attacker can use a browser to exploit this issue.
The following example URIs is available:
http://www.example.com/path/admin/NewsManager/update.asp?ItemID=[SQL ATTACK]
http://www.example.com/path/admin/SecureDocumentLibrary/DocumentLibraryManager/update.asp?ItemID=xx[SQL ATTACK]
Solution / Fix
Multiple DMXReady Products 'ItemId' Parameter SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple DMXReady Products 'ItemId' Parameter SQL Injection Vulnerability
References:
References:
- DmxReady Bilboard v1.2 SQL Injection Vulnerability (Bellatrix)
- DmxReady Contact Us Manager v1.2 SQL Injection Vulnerability (Bellatrix)
- DmxReady Document Library Manager v1.2 SQL Injection Vulnerability (DMXReady)
- DmxReady Faqs Manager v1.2 SQL Injection Vulnerability (Bellatrix)
- DmxReady News Manager v1.2 SQL Injection Vulnerability (DMXReady)
- Vendor Homepage (DMXready)