[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Coupon Script v6.0 - SQL Injection Vulnerability

Author
Chokri B.A.
Risk
[
Security Risk High
]
0day-ID
0day-ID-18273
Category
web applications
Date add
15-05-2012
Platform
windows
Title:
======
Coupon Script v6.0 - SQL Injection Vulnerability

Introduction:
=============
PHP Coupon Software Script is a Powerful and Robust Internet Software Program Developed to provide 
an affordable and easy way to operate local and National Full Page Coupon Advertisements for local 
and Business directory owners and entrepreneurs seeking income opportunities. By Selling Coupons 
along with Full page Advertisements for your Advertisers and Clients you have the ability and 
flexibility to offer a more efficient, cost cutting, Faster and more flexible way for your clients 
to advertise, rather than advertising in a local newspaper, Your customers will appreciate the ease 
of creating and editing their Full Page Coupon and Business advertisement Page instantly online 
24 hours a day 7 days a week.

(Copy of the Vendor Homepage: http://www.couponscript.com/ )

Details:
========
An SQL Injection vulnerability is detected on the PHP Coupon Script version 6.0 (latest).
The vulnerability allows an attacker (remote) to inject/execute own sql commands on the affected application dbms. 
Successful exploitation of the vulnerability results in dbms, service & application compromise.
The vulnerabilities are located on the id value of the file `index.php` request.

Vulnerable Module(s):
								[+] index.php

Vulnerable Value(s):		
								[+] bus=



#  0day.today [2024-11-16]  #