vendor:
webSPELL
by:
DNX
7.5
CVSS
HIGH
Remote SQL Injection
CWE
Product Name: webSPELL
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
webSPELL v4.01.02 (showonly) Remote SQL Injection
This exploit takes advantage of an unquoted variable in the news.php file of webSPELL v4.01.02, allowing for remote SQL injection. The exploit can only be used if the register_globals setting is turned on. It requires the host and path of the target, as well as optional parameters for the user ID and table name. The exploit uses a loop to retrieve the MD5 hash character by character.
Mitigation:
Install the security fix for webSPELL v4.01.02.