WHMCS PayPal and Google Checkout Modules Security Bypass and SQL Injection Vulnerabilities
BID:57149
Info
WHMCS PayPal and Google Checkout Modules Security Bypass and SQL Injection Vulnerabilities
| Bugtraq ID: | 57149 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2012 12:00AM |
| Updated: | Dec 03 2012 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
WHMCS WHMCS 5.1.2 WHMCS WHMCS 4.5.2 |
| Not Vulnerable: |
WHMCS WHMCS 5.1.3 WHMCS WHMCS 4.5.3 |
Discussion
WHMCS PayPal and Google Checkout Modules Security Bypass and SQL Injection Vulnerabilities
WHMCS is prone to a security-bypass vulnerability and an SQL-injection vulnerability.
An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
WHMCS versions prior to 4.5.3 and 5.1.3 are vulnerable.
WHMCS is prone to a security-bypass vulnerability and an SQL-injection vulnerability.
An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
WHMCS versions prior to 4.5.3 and 5.1.3 are vulnerable.
Exploit / POC
WHMCS PayPal and Google Checkout Modules Security Bypass and SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
WHMCS PayPal and Google Checkout Modules Security Bypass and SQL Injection Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
WHMCS PayPal and Google Checkout Modules Security Bypass and SQL Injection Vulnerabilities
References:
References: