vendor:
Invision Power Top Site List & Invision Gallery
by:
James Bercegay
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Invision Power Top Site List & Invision Gallery
Affected Version From: <= 1.1 RC 2
Affected Version To: <= 1.0.1
Patch Exists: NO
Related CWE: CVE-2004-1835
CPE: a:invision_power_services:invision_power_top_site_list
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2004
Invision Power Top Site List SQL Injection
Invision Power Top Site List is prone to an SQL Injection vuln in its 'comment' feature. This issue is very much exploitable as the injection happens right in the middle of a WHERE statement. An attacker can execute arbitrary requests, such as pulling the admin hash and/or possibly taking admin control over an affected Invision Power Top Site List. An example URL to exploit this vulnerability is index.php?act=comments&id=[Evil_Query].
Mitigation:
The Invision Power Services team were contacted immediately and hopefully a fix will be available soon.