PostCalendar Search Function SQL Injection Vulnerability
BID:9372
Info
PostCalendar Search Function SQL Injection Vulnerability
| Bugtraq ID: | 9372 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2004 12:00AM |
| Updated: | Jan 03 2004 12:00AM |
| Credit: | Discovery is credited to Klavs Klavsen. |
| Vulnerable: |
PostCalendar Development Team PostCalendar 4.0 .0 |
| Not Vulnerable: |
PostCalendar Development Team PostCalendar 4.0.1 |
Discussion
PostCalendar Search Function SQL Injection Vulnerability
PostCalendar is prone to an SQL injection vulnerability. The software does not adequately filter SQL syntax from user-supplied input before including it in a database query. As a result, remote attackers may influence the logic and structure of database queries made by the software.
This vulnerability could potentially be exploited to compromise the bulletin board installation, disclose sensitive information from within the database or even to launch attacks against the database implementation.
PostCalendar is prone to an SQL injection vulnerability. The software does not adequately filter SQL syntax from user-supplied input before including it in a database query. As a result, remote attackers may influence the logic and structure of database queries made by the software.
This vulnerability could potentially be exploited to compromise the bulletin board installation, disclose sensitive information from within the database or even to launch attacks against the database implementation.
Exploit / POC
PostCalendar Search Function SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PostCalendar Search Function SQL Injection Vulnerability
Solution:
This issue has been addressed in PostCalendar 4.0.1.
PostCalendar Development Team PostCalendar 4.0 .0
Solution:
This issue has been addressed in PostCalendar 4.0.1.
PostCalendar Development Team PostCalendar 4.0 .0
-
PostCalendar Development Team postcalendar-4.0.1-fixpackage.zip
Fixed files only.
http://noc.postnuke.com/download.php/244/postcalendar-4.0.1-fixpackage .zip -
PostCalendar Development Team postcalendar-4.0.1.zip
http://noc.postnuke.com/download.php/243/postcalendar-4.0.1.zip
References
PostCalendar Search Function SQL Injection Vulnerability
References:
References:
- PostCalendar Security Advisory PCSA 2004-1 (PostNuke Development Team)