Release date:
Updated on: 2012-10-02
Affected Systems:
Php-X-Links Script
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51223
CVE (CAN) ID: CVE-2012-5098
Php-X-Links Script is a simple interface for storing all Links in a centralized location on the network.
Php-X-Links Script 1.0 and other versions have multiple SQL Injection Vulnerabilities. Successful exploitation of these vulnerabilities allows attackers to control applications, access or modify data.
<* Source: H4ckCity Security Team
Link: http://www.exploit-db.com/exploits/18298/
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/links/rate.php? Id = [SQLi]
Http://www.example.com/links/view.php? Cid = [SQLi]
Http://www.example.com/links/pop.php? T = [SQLi]
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Php-X-Links
-----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.allthescripts.com/page-417.htm