eStore Login.PHP SQL Injection Vulnerability
BID:8219
Info
eStore Login.PHP SQL Injection Vulnerability
| Bugtraq ID: | 8219 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2003 12:00AM |
| Updated: | Jul 17 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Bosen <[email protected]>. |
| Vulnerable: |
Brooky eStore 1.0.2 b Brooky eStore 1.0.2 Brooky eStore 1.0.1 |
| Not Vulnerable: | |
Discussion
eStore Login.PHP SQL Injection Vulnerability
eStore login.php has been reported prone to an SQL Injection Vulnerability.
It has been reported that the login.php script contained in the eStore software fails to sufficiently sanitize user input. A remote attacker may exploit this issue to influence SQL query logic. Although unconfirmed, this may allow the attacker to bypass authentication methods. Other attacks, including attacks on the underlying database may also be possible.
eStore login.php has been reported prone to an SQL Injection Vulnerability.
It has been reported that the login.php script contained in the eStore software fails to sufficiently sanitize user input. A remote attacker may exploit this issue to influence SQL query logic. Although unconfirmed, this may allow the attacker to bypass authentication methods. Other attacks, including attacks on the underlying database may also be possible.
Exploit / POC
eStore Login.PHP SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
eStore Login.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
eStore Login.PHP SQL Injection Vulnerability
References:
References:
- eStore Homepage (Brooky)
- eStore SQL Injection Vulnerability & Path Disclosure (Bosen
)