LiteRadius 'locator.php' Multiple SQL Injection Vulnerabilities
BID:48665
Info
LiteRadius 'locator.php' Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 48665 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2011 12:00AM |
| Updated: | Jul 13 2011 12:00AM |
| Credit: | Robert Cooper |
| Vulnerable: |
LiteRadius LiteRadius 3.2 |
| Not Vulnerable: | |
Discussion
LiteRadius 'locator.php' Multiple SQL Injection Vulnerabilities
LiteRadius is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
LiteRadius versions 3.2 and prior are vulnerable.
LiteRadius is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
LiteRadius versions 3.2 and prior are vulnerable.
Exploit / POC
LiteRadius 'locator.php' Multiple SQL Injection Vulnerabilities
The following example URI is available:
http://www.example.com/dealer/locator.php?parsed_page=1&lat=25.4405436315&long=132.710253334'
The following example URI is available:
http://www.example.com/dealer/locator.php?parsed_page=1&lat=25.4405436315&long=132.710253334'
Solution / Fix
LiteRadius 'locator.php' Multiple SQL Injection Vulnerabilities
Solution:
Currently, we are not aware of any patches. If you feel we are in error or if you are aware of more recent
information, please mail us at: [email protected]..
Solution:
Currently, we are not aware of any patches. If you feel we are in error or if you are aware of more recent
information, please mail us at: [email protected]..