The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


ZH2004-04SA (security advisory): Multiple Sql Injection Vulnerabilities in ReviewPost PHP Pro


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 4 Feb 2004 08:33:22 -0000
From: ZetaLabs <zetalabs@zone-h org>
To: bugtraq@securityfocus com
Subject: ZH2004-04SA (security advisory): Multiple Sql Injection Vulnerabilities in ReviewPost PHP Pro



ZH2004-04SA (security advisory): Multiple Sql Injection Vulnerabilities in ReviewPost PHP Pro

Published: 04 february 2004

Released: 04 february 2004

Name: ReviewPost PHP Pro

Affected Systems: current and prior versions

Issue: Sql Injection Vulnerability

Author: G00db0y from Zone-h Security Labs - zetalabs@zone-h org

Vendor: http://www reviewpost com




Description

***********

Zone-h Security Team has discovered a flaw in PhotoPost PHP Pro  There is a vulnerability in the current version (and also in prior versions) of PhotoPost PHP Pro that allows an attacker to disclose sensitive information that could be used to gain unauthorized access 
"Your community of users represents a wealth of knowledge  Now your users can help build and maintain your site by writing reviews of any product imaginable  With ReviewPost, you will quickly amass a valuable collection of user opinions about products that relate to your site "





Details

******* 


The problems exist due to insufficient sanitization of user-supplied data  A remote attacker may exploit these issues to influence SQL query logic to disclose sensitive information that could be used to gain unauthorized access 

For example try this:

http://address/directory/showproduct php?product=[query]

http://address/directory/showcat php?cat=[query]




Solution:

*********

The vendor has been contacted and a patch was produced:

http://www photopost com/members/forum/showthread php?s=&threadid=98098



G00db0y from Zone-h Security Labs - zetalabs@zone-h org



http://www zone-h org/en/advisories/read/id=3864/

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру