PHPCatalog ID Parameter SQL Injection Vulnerability
BID:9318
Info
PHPCatalog ID Parameter SQL Injection Vulnerability
| Bugtraq ID: | 9318 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2003 12:00AM |
| Updated: | Dec 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to David Sopas Ferreira. |
| Vulnerable: |
SILICONSYS PHPCatalog 2.6.7 SILICONSYS PHPCatalog 2.6.6 SILICONSYS PHPCatalog 2.6.2 SILICONSYS PHPCatalog 2.5.1 |
| Not Vulnerable: |
SILICONSYS PHPCatalog 2.6.10 |
Discussion
PHPCatalog ID Parameter SQL Injection Vulnerability
A vulnerability has been reported to exist in PHPCatalog that may allow a remote user to inject malicious SQL syntax into database queries. The problem reportedly exists in the URI parameters of PHPCatalog. This issue is caused by insufficient sanitization of user-supplied data. A remote attacker may exploit this issue to influence SQL query logic to have unauthorized SQL queries executed in the database.
A vulnerability has been reported to exist in PHPCatalog that may allow a remote user to inject malicious SQL syntax into database queries. The problem reportedly exists in the URI parameters of PHPCatalog. This issue is caused by insufficient sanitization of user-supplied data. A remote attacker may exploit this issue to influence SQL query logic to have unauthorized SQL queries executed in the database.
Exploit / POC
PHPCatalog ID Parameter SQL Injection Vulnerability
The following proof of concept has been supplied:
The following proof of concept has been supplied:
Solution / Fix
PHPCatalog ID Parameter SQL Injection Vulnerability
Solution:
The vendor has reportedly released an update (2.6.10) to address this issue. Users are advised to contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has reportedly released an update (2.6.10) to address this issue. Users are advised to contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.