MachForm CVE-2013-4948 SQL Injection Vulnerability
BID:60910
Info
MachForm CVE-2013-4948 SQL Injection Vulnerability
| Bugtraq ID: | 60910 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4948 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2013 12:00AM |
| Updated: | Aug 01 2013 09:25PM |
| Credit: | Yashar shahinzadeh |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
MachForm CVE-2013-4948 SQL Injection Vulnerability
MachForm is prone to an SQL-injection vulnerability because it fails to sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Note: The issue (described by CVE-2013-4949) has been moved to BID 61569 (MachForm CVE-2013-4949 Arbitrary File Upload Vulnerability) to better document it.
MachForm is prone to an SQL-injection vulnerability because it fails to sanitize user-supplied data.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Note: The issue (described by CVE-2013-4949) has been moved to BID 61569 (MachForm CVE-2013-4949 Arbitrary File Upload Vulnerability) to better document it.
Exploit / POC
MachForm CVE-2013-4948 SQL Injection Vulnerability
An attacker can use a browser to exploit this issue.
The following example POST request data for SQL-injection is available:
element_1=1&element_2=%27%22%28%29%26%251%3cScRiPt%20%3eprompt%28949236%29%3c%2fScRiPt%3e&element_3=1&form_id=11&submit=Enviar
An attacker can use a browser to exploit this issue.
The following example POST request data for SQL-injection is available:
element_1=1&element_2=%27%22%28%29%26%251%3cScRiPt%20%3eprompt%28949236%29%3c%2fScRiPt%3e&element_3=1&form_id=11&submit=Enviar
Solution / Fix
MachForm CVE-2013-4948 SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MachForm CVE-2013-4948 SQL Injection Vulnerability
References:
References: