Home aeyStudio
Welcome Guest · Registration
Resources
Download Seportal
Demo Site
SePortal Sites

Users
Username:

Password:

Log me on automatically next visit?


» Forgot password
» Registration

Topics
Home
Seportal (5)
News (3)

Who is Online
Currently active users: 2
There are currently 0 registered user(s) (0 among them invisible) and 2 guest(s) online.

Random Image
Ana Sayfa/Home

Ana Sayfa/Home
Comments: 0
zebaniz

Powered By
Powered by SePortal

Rate SePortal at
Listed at Hot Scripts in PHP

Scripts.com


ScriptSearch.com


PHP



Add Reply New Topic

> Cok önemli 2 güvenlik acigi
 
 
Messenger
Posted: 07.12.2008 - 18:36
Quote


Member
*

Group: Üyeler
Total posts: 4
User No: 176
Join Date: 09.10.2008 19:12



 
Seportalin 2 tane cok önemli güvenirlik acigi var.Acilen cözülmesi gerekiyor.

SePortal 'poll.php' SQL Injection Vulnerability

SePortal is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

SePortal 2.4 is vulnerable; other versions may also be affected.
SePortal 'poll.php' SQL Injection Vulnerability

An attacker can exploit this issue through a web browser.

The following example URI is available.

http://www.example.com/poll.php? poll_id=1'+union+select+1,convert(concat_ws(0x3a3a
,user_name,user_password)+using+latin1),1,1,1,1,1,
1,1,1+from+seportal_users+limit+1,1/*


Some vulnerabilities in SePortal, which can be exploited by malicious people to conduct SQL injection attacks.

Input passed to the "poll_id" parameter in poll.php and to the "sp_id" parameter in staticpages.php is not properly sanitised before being used in an SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

The vulnerabilities are reported in version 2.4. Other versions may also be affected.

Solution

Edit the source code to ensure that input is properly sanitised.



Lütfen bu aciklari en kisa zamanda kapatalim.!!!
Offline Messenger
Top
 
borak07
Posted: 17.12.2009 - 21:59
Quote


Member
*

Group: Üyeler
Total posts: 8
User No: 256
Join Date: 17.12.2009 20:14



 
2.5 versiyonunda bu sorun giderilmiş sanırım. Eski versiyonları kullananların 2.5 upgrate dosyalarını indirmeleri lazım.
Offline BoraK
Top

Add Reply New Topic



Contribute | Forums | Gallery | Calendar | Links | Downloads | Members | Search | Guestbook | Article Directory

Powered by SePortal 2.5
Copyright © 2007-2010 SePortal.org