Flynax Multiple Products Multiple SQL Injection Vulnerabilities
BID:49788
Info
Flynax Multiple Products Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 49788 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2011 12:00AM |
| Updated: | Sep 25 2011 12:00AM |
| Credit: | Nasel Penetration Testing team |
| Vulnerable: |
Flynax Real Estate Classifieds 3.2 Flynax Pets Classifieds Software 3.2 Flynax General Classifieds Software 3.2 Flynax Auto Classifieds Script 3.2 |
| Not Vulnerable: | |
Discussion
Flynax Multiple Products Multiple SQL Injection Vulnerabilities
Multiple Flynax products are prone to multiple SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Multiple Flynax products are prone to multiple SQL-injection vulnerabilities because they fail to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Flynax Multiple Products Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
References
Flynax Multiple Products Multiple SQL Injection Vulnerabilities
References:
References:
- Vendor Homepage (Flynax)