// you’re reading...

Advisories

Zoki Catalog SQL Injection

Ref. [DSF-02-2009] – Zoki Catalog SQL Injection
Vendor: Zoki Soft
Status: Patched by vendor

Zoki Catalog
Smart Catalog is unique and convenient software. It is designed for many purposes whether you want to create blog, product catalog, classifieds, events, jobs or many others. This software gives you opportunity to create general categories and unlimited number of subcategories, create static pages, upload images, rate and comment listings. The Smart Catalog has SEO optimized URLs, RSS feeds and fast indexed with major search engines.

Description
This PHP based catalog is vulnerable to SQL Injection on search form.
Injecting a quote mark will break the SQL query and even provide sensitive database information that could help a malicious user to complete and enter a valid SQL injection query.

Impact
A malicious user could manipulate SQL queries by injecting arbitrary SQL code and return private information.

Time-line
June 3, 2009 – Reported to Zoki Soft
June 13, 2009 – Reply from vendor
June 15, 2009 – Vendor fixed it

Disclosed
SA35476BugtraqCVE-2009-2097

Imagem 1

Discussion

No comments for “Zoki Catalog SQL Injection”

Post a comment