PHP TopSites edit.php SQL Injection Vulnerability
BID:6625
Info
PHP TopSites edit.php SQL Injection Vulnerability
| Bugtraq ID: | 6625 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2003 12:00AM |
| Updated: | Jan 15 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to the Cyberarmy Application and Code Auditing Team <[email protected]>. |
| Vulnerable: |
iTop10 PHP TopSites Pro 2.2 iTop10 PHP TopSites Free 2.0 B |
| Not Vulnerable: | |
Discussion
PHP TopSites edit.php SQL Injection Vulnerability
A vulnerability has been discovered in PHP TopSites. Due to insufficient sanitization of user-supplied URI parameters it is possible for an attacker to embed SQL commands into certain page requests. This may result in another users private information being disclose to an attacker.
A vulnerability has been discovered in PHP TopSites. Due to insufficient sanitization of user-supplied URI parameters it is possible for an attacker to embed SQL commands into certain page requests. This may result in another users private information being disclose to an attacker.
Exploit / POC
PHP TopSites edit.php SQL Injection Vulnerability
The following proof of concept has been made available:
http://examplewebsite.com/topsitesdirectory/edit.php?a=pre&submit=&sid=siteidnumber--
The following proof of concept has been made available:
http://examplewebsite.com/topsitesdirectory/edit.php?a=pre&submit=&sid=siteidnumber--
Solution / Fix
PHP TopSites edit.php SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP TopSites edit.php SQL Injection Vulnerability
References:
References:
- Multiple PHP Topsites Vulnerabities found (Cyberarmy Application and Code Auditing Team
)