Vulnerability Information
Lore is a web-based article management system.
Lore does not adequately filter user-submitted URIs, and remote attackers can exploit vulnerabilities for SQL injection attacks to obtain sensitive information.
The problem is that the ' article.php ' script lacks sufficient filtering for user-submitted ' id ' parameters, submits a malicious SQL query as parameter data, can change the original SQL logic, obtain sensitive information, or possibly manipulate the database.
Bugtraq id:15665
Cncan id:cncan-2005120207
Vulnerability message time: 2005-12-01
Vulnerability causes
Input validation Error
Impact system
Lore 1.5.4
Harm
Remote attackers can exploit vulnerabilities for SQL injection attacks to obtain sensitive information.
Conditions required for the attack
An attacker would have to access lore.
Test method
Http://www.example.com/article.php?id=1[sql]
Vendor Solutions
There are no solutions available at this time, please follow the links below:
Http://www.pineappletechnologies.com/PRoducts/lore
Vulnerability Provider
r0t
Vulnerability Message Link
Http://pridels.blogspot.com/2005/12/lore-sql-inj-vuln.html
Vulnerability message Header
Lore SQL Inj. Vuln.