Xpressions Interactive Multiple SQL Injection Vulnerabilities
BID:7804
Info
Xpressions Interactive Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 7804 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2003 12:00AM |
| Updated: | Jun 04 2003 12:00AM |
| Credit: | Discovery of these vulnerabilities credited to "Paul Craig" <[email protected]>. |
| Vulnerable: |
Xpressions Interactive Website Integration Xpressions Interactive trueConnect Xpressions Interactive FlowerLink Xpressions Interactive eVision |
| Not Vulnerable: | |
Discussion
Xpressions Interactive Multiple SQL Injection Vulnerabilities
Several software products maintained by Xpressions Interactive are prone to SQL injection attacks.
The vulnerability exists in the login.asp page. Specifically, user-supplied input is not sufficiently sanitized of malicious SQL queries.
An attacker may exploit this vulnerability to insert SQL code into requests and have the SQL code executed by the underlying database server.
Several software products maintained by Xpressions Interactive are prone to SQL injection attacks.
The vulnerability exists in the login.asp page. Specifically, user-supplied input is not sufficiently sanitized of malicious SQL queries.
An attacker may exploit this vulnerability to insert SQL code into requests and have the SQL code executed by the underlying database server.
Exploit / POC
Xpressions Interactive Multiple SQL Injection Vulnerabilities
The following proof of concept was provided:
http://examplestore.com/manage/login.asp
User: admin
Pass: ' or '1' = '1
The following proof of concept was provided:
http://examplestore.com/manage/login.asp
User: admin
Pass: ' or '1' = '1
Solution / Fix
Xpressions Interactive Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Xpressions Interactive Multiple SQL Injection Vulnerabilities
References:
References:
- Xpressions Interactive (Xpressions Interactive)
- Xpressions Software: Multiple SQL Injection Attacks To Manage WebStore ("Paul Craig"
)