Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

PHPAUCTION Multiple Vulnerabilities

High

Synopsis

The remote web server contains a script that is vulnerable to a SQL injection attack.

Description

The remote host is running PHPAUCTION, a web-based auction portal. This version of PHPAUCTION is vulnerable to multiple injection flaws. The application fails to properly sanitize user input and, consequently, is prone to remote attacks. The attacks include HTML injection as well as SQL injection. An attacker exploiting these flaws would only need to be able to send malformed HTTP requests to the application. Successful exploitation would result in possible database compromise or arbitrary code being executed either on the server or within an unsuspecting user's browser.

Solution

No solution is known at this time.