header-logo
Suggest Exploit
vendor:
iClone
by:
Sid3^effects aKa HaRi
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: iClone
Affected Version From: iClone4
Affected Version To: iClone4
Patch Exists: NO
Related CWE: N/A
CPE: a:reallusion:iclone
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010

iClone SQLi Vulnerability

Real-time animation evolves with 3D Video FX, motion paths, HDR and rapid drag & drop creation inside iClone4. iClone4 introduces new features that combine video production with 3D real-time animation. The result is a powerful production tool for motion graphics, 3D animation and video compositing.

Mitigation:

Input validation and sanitization should be done to prevent SQL injection attacks.
Source

Exploit-DB raw data:

1               ##########################################             1
0               I'm Sid3^effects member from Inj3ct0r Team             1
1               ##########################################             0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Name : iClone SQLi Vulnerability
Date : june, 9 2010
Vendor url :http://www.reallusion.com/iclone/
Platform: Windows
Price:$199
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,gunslinger_
greetz to :All ICW members.

###############################################################################################################
Description:

Real-time animation evolves with 3D Video FX, motion paths, HDR and rapid drag & drop creation inside iClone4. iClone4 introduces new features that combine video production with 3D real-time animation. The result is a powerful production tool for motion graphics, 3D animation and video compositing.
###############################################################################################################

Xploit: SQLi Vulnerability

DEMO  URL:

  http://site.com/reallusiontv/ic/productdemo.asp?page=[SQLi]


###############################################################################################################
# 0day no more 
# Sid3^effects