Autorank PHP Multiple SQL Injection Vulnerabilities
BID:9251
Info
Autorank PHP Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 9251 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2003 12:00AM |
| Updated: | Dec 18 2003 12:00AM |
| Credit: | Discovery is credited to JeiAr <[email protected]>. |
| Vulnerable: |
JMB Software AutoRank PHP 2.0.4 |
| Not Vulnerable: | |
Discussion
Autorank PHP Multiple SQL Injection Vulnerabilities
AutoRank PHP is prone to multiple SQL injection vulnerabilities, which are exposed via various form-based input fields. Remote attackers may potentially exploit this issue to compromise security properties of the software, gain access to sensitive information or possibly even launch attacks against the underlying database implementation.
This issue was reported in version 2.0.4 of the software. Other versions may also be affected.
AutoRank PHP is prone to multiple SQL injection vulnerabilities, which are exposed via various form-based input fields. Remote attackers may potentially exploit this issue to compromise security properties of the software, gain access to sensitive information or possibly even launch attacks against the underlying database implementation.
This issue was reported in version 2.0.4 of the software. Other versions may also be affected.
Exploit / POC
Autorank PHP Multiple SQL Injection Vulnerabilities
There is no exploit required.
There is no exploit required.
Solution / Fix
Autorank PHP Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Autorank PHP Multiple SQL Injection Vulnerabilities
References:
References:
- AutoRank PHP Homepage (JMB Software)
- Autorank PHP SQL Injection Vulnerabilities (JeiAr
)