All Enthusiast ReviewPost PHP Pro Multiple SQL Injection Vulnerabilities
BID:9574
Info
All Enthusiast ReviewPost PHP Pro Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 9574 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2004 12:00AM |
| Updated: | Feb 04 2004 12:00AM |
| Credit: | The disclosure of these issues has been credited to G00db0y from Zone-h Security Labs <[email protected]>. |
| Vulnerable: |
All Enthusiast Inc ReviewPost PHP Pro 2.5.1 All Enthusiast Inc ReviewPost PHP Pro 2.5 |
| Not Vulnerable: | |
Discussion
All Enthusiast ReviewPost PHP Pro Multiple SQL Injection Vulnerabilities
It has been reported that ReviewPost PHP Pro may be prone to multiple SQL injection vulnerabilities that may allow an attacker to influence SQL query logic. This issue could be exploited to disclose sensitive information that may be used to gain unauthorized access. An attacker may pass malicious data via the 'product' parameter of 'showproduct.php' script and the 'cat' parameter of 'showcat.php' script.
Although unconfirmed, ReviewPost PHP Pro 2.5.1 and prior may be prone to these issues.
It has been reported that ReviewPost PHP Pro may be prone to multiple SQL injection vulnerabilities that may allow an attacker to influence SQL query logic. This issue could be exploited to disclose sensitive information that may be used to gain unauthorized access. An attacker may pass malicious data via the 'product' parameter of 'showproduct.php' script and the 'cat' parameter of 'showcat.php' script.
Although unconfirmed, ReviewPost PHP Pro 2.5.1 and prior may be prone to these issues.
Exploit / POC
All Enthusiast ReviewPost PHP Pro Multiple SQL Injection Vulnerabilities
No exploit code is required to exploit these issues.
The following proof of concept has been provided:
http://www.example.com/directory/showproduct.php?product=[query]
http://www.example.com/directory/showcat.php?cat=[query]
No exploit code is required to exploit these issues.
The following proof of concept has been provided:
http://www.example.com/directory/showproduct.php?product=[query]
http://www.example.com/directory/showcat.php?cat=[query]
Solution / Fix
All Enthusiast ReviewPost PHP Pro Multiple SQL Injection Vulnerabilities
Solution:
The vendor has released a patch to address these issues. Users are advised to contact the vendor in order to obtain the patch.
Solution:
The vendor has released a patch to address these issues. Users are advised to contact the vendor in order to obtain the patch.
References
All Enthusiast ReviewPost PHP Pro Multiple SQL Injection Vulnerabilities
References:
References:
- ReviewPost PHP Pro (All Enthusiast Inc)
- Security Update: ReviewPost 2.5.1 (All Enthusiast Inc)
- ZH2004-04SA (security advisory): Multiple Sql Injection Vulnerabilities (ZetaLabs
)