GoldLink Cookie SQL Injection Vulnerability
BID:8847
Info
GoldLink Cookie SQL Injection Vulnerability
| Bugtraq ID: | 8847 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2003 12:00AM |
| Updated: | Oct 18 2003 12:00AM |
| Credit: | Discovery is credited to "Weke" <[email protected]>. |
| Vulnerable: |
GoldScripts GoldLink 3.0 |
| Not Vulnerable: | |
Discussion
GoldLink Cookie SQL Injection Vulnerability
GoldLink is prone to SQL injection attacks. This is due to insufficient validation of values supplied via cookies. As a result, it may be possible to manipulate SQL queries, potentially resulting in information disclosure, bulletin board compromise or other consequences.
GoldLink is prone to SQL injection attacks. This is due to insufficient validation of values supplied via cookies. As a result, it may be possible to manipulate SQL queries, potentially resulting in information disclosure, bulletin board compromise or other consequences.
Exploit / POC
GoldLink Cookie SQL Injection Vulnerability
The following example cookie fields were provided:
vadmin_login = ' OR Login LIKE '%
and
vadmin_pass = ' OR Password LIKE '%
The following example cookie fields were provided:
vadmin_login = ' OR Login LIKE '%
and
vadmin_pass = ' OR Password LIKE '%
Solution / Fix
GoldLink Cookie SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GoldLink Cookie SQL Injection Vulnerability
References:
References:
- GoldLink Homepage (GoldScripts)
- Get admin level on Goldlink script v3.0 ("Weke"
)