Release date:
Updated on:
Affected Systems:
Horizon QCMS <= 4.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64715
CVE (CAN) ID: CVE-2013-7139
Horizon QCMS is an open-source quick content management system that supports PHP and MySQL.
Horizon QCMS 4.0 and earlier versions are not properly filtered "/download. the "category" http post parameter in the php "script has the SQL injection vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary SQL commands in the application database.
<* Source: High-Tech Bridge Security Research Lab
Link: http://seclists.org/bugtraq/2014/Jan/16
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http: // [host]/download. php? Category = % 27% 20 union % 20 select % 6%, version (), 202, 20 -- %
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Horizon QCMS
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.hnqcms.com/
Reference: http://sourceforge.net/projects/hnqcms/files/patches/