Release date:
Updated on:
Affected Systems:
Beat Websites 1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56683
Beat Websites is an online music product sales website.
The id parameter of the page_detail.php page of Beat Websites 1.0 and other versions has the SQL injection vulnerability. Attackers can exploit this vulnerability to access the database without authorization and obtain important information.
<* Source: Metropolis
Link: http://www.idglabs.net/news/beat-websites-blind-sql-injection.html
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/page_detail.php? Id = 1 and 1 = 1
Http://www.example.com/page_detail.php? Id = 1 and 1 = 2
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
Modify the Code. If the id value is not a number, no SQL query is executed.
Vendor patch:
Beat Websites
-------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://beatwebsites.com/