Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
BID:9196
Info
Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
| Bugtraq ID: | 9196 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2003 12:00AM |
| Updated: | Dec 10 2003 12:00AM |
| Credit: | This issue was reported by Chintan Trivedi <[email protected]>. |
| Vulnerable: |
Mambo Mambo Site Server 4.0.14 |
| Not Vulnerable: | |
Discussion
Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
It has bee reported that Mambo Open Source 4.0.14 Server is prone to SQL injection attacks. The problem is said to occur due to insufficient sanitization of data passed to specific index.php variables. As a result, an attacker may be capable of influencing the logic of specific queries or statements made by the underlying database. This could ultimately result in a number of attacks being carried out against the system.
It has bee reported that Mambo Open Source 4.0.14 Server is prone to SQL injection attacks. The problem is said to occur due to insufficient sanitization of data passed to specific index.php variables. As a result, an attacker may be capable of influencing the logic of specific queries or statements made by the underlying database. This could ultimately result in a number of attacks being carried out against the system.
Exploit / POC
Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
No exploit required. The following proof of concept has been supplied.
http://www.example.com/index.php?option=articles&task=viewarticle&artid=5%20UNION%20somequery
No exploit required. The following proof of concept has been supplied.
http://www.example.com/index.php?option=articles&task=viewarticle&artid=5%20UNION%20somequery
Solution / Fix
Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mambo Open Source 4.0.14 Server SQL Injection Vulnerability
References:
References:
- Mambo Open Source 4.0.14 SQL injection (Chintan Trivedi
)