VulDB: WebMaster Solutions WmsCms default.asp/printpage.asp Eingabe SQL Injection
General
scipID: 5339
Affected: WebMaster Solutions WmsCms
Published: 06/06/2010 (MG)
Risk:
problematic
Entry: 92% complete
Created: 05/08/2012
Updated: 09/03/2012
Summary
A vulnerability was found in WebMaster Solutions WmsCms and classified as problematic. This issue affects an unknown function of the file default.asp/printpage.asp. The manipulation as part of a Eingabe leads to a sql injection vulnerability. Impacted is confidentiality, integrity, and availability.
The weakness was shared 06/06/2010 by MG with Ariko-Security as 65465 as knowledge base article (OSVDB). The advisory is shared for download at osvdb.org. The vendor was not invovled in the public release. The identification of this vulnerability is CVE-2010-2317 since 06/17/2010. The exploitability is told to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. Technical details as well as a public exploit are known.
An exploit has been developed by MG and been published even before and not after the advisory. The exploit is shared for download at exploit-db.com. The vulnerability was handled as a non-public zero-day exploit for at least 27 days. By approaching the search of inurl:default.asp/printpage.asp it is possible to find vulnerable targets with Google Hacking.
There are no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product. The vulnerability is also documented in the databases at OSVDB (65465) and Secunia (SA25583). wmsdesign.net is providing further details.
CVSS
Base Score: 7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P) [?]
| Access Vector | Access Complexity | Authentication | Confidentiality | Integrity | Availability |
|---|---|---|---|---|---|
| Local | High | Multiple | None | None | None |
| Adjacent | Medium | Single | Partial | Partial | Partial |
| Network | Low | None | Complete | Complete | Complete |
Exploiting
Class: SQL Injection
Local: No
Remote: Yes
Availability: Yes
Access: Public
Author: MG
Download: exploit-db.com
Google Hack: inurl:default.asp/printpage.asp
Countermeasures
Recommended: no mitigation known
0-Day Time: 27 days since found
Timeline
05/10/2010 | Vendor informed
06/05/2010 | Exploit disclosed
06/06/2010 | Advisory disclosed
06/12/2010 | OSVDB entry created
06/17/2010 | CVE assigned
05/08/2012 | VulDB entry created
09/03/2012 | VulDB entry updated
Sources
Advisory: 65465
Researcher: MG
Company: Ariko-Security
OSVDB: 65465
CVE: CVE-2010-2317 (mitre.org) (nist.org) (cvedetails.com)
Secunia: 25583
Vupen: ADV-2010-1361
Misc.: wmsdesign.net
- Latest Entries
- Apple QuickTime DREF Atom Handler buffer overflow [CVE-2013-1017]
- Apple QuickTime H.264 Handler buffer overflow [CVE-2013-1018]
- Apple QuickTime MP3 File Handler buffer overflow [CVE-2013-0989]
- Apple QuickTime Sorenson Codec Handler buffer overflow [CVE-2013-1019]
- Apple QuickTime JPEG Handler buffer overflow [CVE-2013-1020]
- Statistics
- Archive



















