Attila PHP SQL Injection Unauthorized Privileged Access Vulnerability
BID:8502
Info
Attila PHP SQL Injection Unauthorized Privileged Access Vulnerability
| Bugtraq ID: | 8502 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2003 12:00AM |
| Updated: | Aug 26 2003 12:00AM |
| Credit: | This vulnerability was reported by Frog Man <[email protected]>. |
| Vulnerable: |
Attila PHP Attila PHP 3.0 |
| Not Vulnerable: | |
Discussion
Attila PHP SQL Injection Unauthorized Privileged Access Vulnerability
An SQL injection vulnerability has been reported in Attila PHP that could allow an attacker to gain unauthorized privileged access to a target site. This could be accomplished by requesting a URI including parameters designed to influence the results of specific user verification checks. Privileged access to a site implementing Attila PHP could allow an attacker to gain sensitive information or launch other attacks.
An SQL injection vulnerability has been reported in Attila PHP that could allow an attacker to gain unauthorized privileged access to a target site. This could be accomplished by requesting a URI including parameters designed to influence the results of specific user verification checks. Privileged access to a site implementing Attila PHP could allow an attacker to gain sensitive information or launch other attacks.
Exploit / POC
Attila PHP SQL Injection Unauthorized Privileged Access Vulnerability
The following example has been provided to demonstrate exploitation:
Set the URI parameter "cook_id" to the value "0 OR visiteur=1" in a request to
http://www.example.org/index.php3
The following example has been provided to demonstrate exploitation:
Set the URI parameter "cook_id" to the value "0 OR visiteur=1" in a request to
http://www.example.org/index.php3
Solution / Fix
Attila PHP SQL Injection Unauthorized Privileged Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Attila PHP SQL Injection Unauthorized Privileged Access Vulnerability
References:
References:
- Attila PHP Home Page (Attila PHP)
- phpsecure Home Page (phpsecure)