[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SelfComposer CMS SQL injection vulnerability

Author
Locu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12207
Category
web applications
Date add
14-05-2010
Platform
php
============================================
SelfComposer CMS SQL injection vulnerability
============================================

Vendor's Description of Software:

# http://www.selfcomposer.it

Dork:

allinurl:"prodotti.asp?idpadrerif="

Application Info:

Name: SelfComposer

Vulnerability Info:

Type: SQL injection Vulnerability

Risk: High

Fix:

N/A

Time Table:

06/05/2010 - Vendor notified.

Additional Info:

All the input passed via "idprod", "idpadrerif", "idreferenza", "idpadrerifIstituzionali"
is not properly sanitised before being used in a sql query.

Solution:

Input validation of "idprod", "idpadrerif", "idreferenza", "idpadrerifIstituzionali"
parameters should be corrected.

Vulnerability:

# http://[site]/scheda.asp?idprod=[SQLi]&idpadrerif=[SQLi]

# http://[site]/schedaistituzionale.asp?idreferenza=[SQLi]&idpadrerifIstituzionali=[SQLi]

Credit:

Discoverd By: Locu

Website: http://xlocux.wordpress.com

Contacts: xlocux[-at-]gmail.com

============ {EOF} =============



#  0day.today [2024-11-14]  #