WHMCS Group Pay Plugin 'hash' Parameter SQL Injection Vulnerability
BID:58751
Info
WHMCS Group Pay Plugin 'hash' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 58751 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2013 12:00AM |
| Updated: | Apr 02 2013 12:00AM |
| Credit: | HJauditing Employee Tim |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WHMCS Group Pay Plugin 'hash' Parameter SQL Injection Vulnerability
Group Pay plugin for WHMCS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Group Pay 1.5 is vulnerable; other versions may also be affected.
Group Pay plugin for WHMCS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Group Pay 1.5 is vulnerable; other versions may also be affected.
Exploit / POC
WHMCS Group Pay Plugin 'hash' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
The following example URI are available:
http://www.example.com/grouppay.php?hash=%hash%' and '1'='1
Attackers can use a browser to exploit this issue.
The following example URI are available:
http://www.example.com/grouppay.php?hash=%hash%' and '1'='1
Solution / Fix
WHMCS Group Pay Plugin 'hash' Parameter SQL Injection Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
WHMCS Group Pay Plugin 'hash' Parameter SQL Injection Vulnerability
References:
References:
- WHMCS Homepage (WHMCS )