[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Pogodny CMS SQL Injection Vulnerability

Author
Ariko-Security
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10926
Category
web applications
Date add
16-02-2010
Platform
unsorted
=======================================
Pogodny CMS SQL Injection Vulnerability
=======================================

# Exploit Title: [Pogodny CMS SQL injection]
# Tested on: [freebsd / ubuntu]
 
============ { Ariko-Security - Advisory #2/2/2010 } =============
 
      SQL injection vulnerability in Pogodny CMS
 
 
Vendor's Description of Software:
# http://www.cms.michalin.pl/moduly/pogodny/  (PL)
 
 
Dork:
#pogodny CMS
 
Application Info:
# Name: pogodny CMS
# Versions: ALL
 
Vulnerability Info:
# Type: SQL injection Vulnerability
# Risk: High
 
Fix:
# N/A Vendor notified 08.02.2010
 
It was found that "pogodny CMS" does not validate properly the "id" parameter
value.
 
Solution:
# Input validation of "id" parameter should be corrected.
 
 
Vulnerability:
# http://server/?modul=niusy&id=61[Sqli]



#  0day.today [2024-06-03]  #