EoCMS SQL injection vulnerability

Source: Internet
Author: User

EoCMS SQL injection vulnerability

1. General information

EoCMS is an open source code software which is used to develop Internet
Forum (http://eocms.com/). On October 15,200 9, Bkis Security detected
SQL injection vulnerability in some functions of eoCMS.

This is a critical vulnerability which allows hacker to access the data
In the database and execute unauthorized tasks. Bkis has informed
Software developer team, and they have patched the vulnerability in
Latest software version-eoCMS 0.9.02.

Details: http://blog.bkis.com /? P = 800
SVRT Advisory: Bkis-12-2009
Initial vendor notification: 11/25/09
Release Date: 11/05/09
Update Date: 11/05/09
Discovered by: Bkis
Attack Type: SQL Injection
Security Rating: Critical
Affected Software: eCMS (version <= 0.9.01)

2. Technical Description

SQL Injection occurs due to the software on Server can not strictly
Control the validity of variables transmitted from client before sending
A query to the database. Hacker is able to take advantage of this
Vulnerability to insert malicious SQL code and then can manipulate all
The data in the database.

SQL Injection vulnerability is found in the page divide function
Viewboard and viewtopic module. Though eoCMS is integrated with error
Control technology (including SQL Injection), this technology fails
Thoroughly handle the errors. Thus, hacker is able to take advantage
The found vulnerability to gain any information from the database,
Including administrators data.

3. Solution

Rating this as a critical vulnerability, Bkis recommends all
Organizations and individuals using eoCMS immediately update the latest
Software version.

---------------------------------------------
Bkis Internet Security (www. bkis. vn)

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.