MyHelpDesk SQL Injection Vulnerability
BID:4971
Info
MyHelpDesk SQL Injection Vulnerability
| Bugtraq ID: | 4971 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0932 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Credited to Ahmet Sabri ALPER <[email protected]>. |
| Vulnerable: |
Luis Bernardo MyHelpDesk 20020509 |
| Not Vulnerable: | |
Discussion
MyHelpDesk SQL Injection Vulnerability
It is reported that MyHelpDesk (version 20020509 and earlier) are vulnerable to SQL injection attacks.
Data supplied by the remote user, via CGI parameters, is used directly as part of SQL statements. As input sanitization is not properly performed, it is possible to modify the logic of a SQL query.
It is reported that MyHelpDesk (version 20020509 and earlier) are vulnerable to SQL injection attacks.
Data supplied by the remote user, via CGI parameters, is used directly as part of SQL statements. As input sanitization is not properly performed, it is possible to modify the logic of a SQL query.
Exploit / POC
MyHelpDesk SQL Injection Vulnerability
The following proof of concept was provided by Ahmet Sabri ALPER <[email protected]>:
http://[TARGET]/supporter/index.php?t=detailticket&id=root%20me
The following proof of concept was provided by Ahmet Sabri ALPER <[email protected]>:
http://[TARGET]/supporter/index.php?t=detailticket&id=root%20me
References
MyHelpDesk SQL Injection Vulnerability
References:
References: