MyTickets 'define.php' Script SQL Injection Vulnerability
BID:54064
Info
MyTickets 'define.php' Script SQL Injection Vulnerability
| Bugtraq ID: | 54064 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2012 12:00AM |
| Updated: | Jun 18 2012 12:00AM |
| Credit: | al-swisre |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
MyTickets 'define.php' Script SQL Injection Vulnerability
MyTickets is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
MyTickets 1.0 through 2.0.8 are vulnerable.
MyTickets is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
MyTickets 1.0 through 2.0.8 are vulnerable.
Exploit / POC
MyTickets 'define.php' Script SQL Injection Vulnerability
An attacker can exploit this issue using a browser.
The following example input is available:
An attacker can exploit this issue using a browser.
The following example input is available:
Solution / Fix
MyTickets 'define.php' Script SQL Injection Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
MyTickets 'define.php' Script SQL Injection Vulnerability
References:
References: