SQL injection in Bigware shop software

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The Bigware shop software prior to version 2.17 contains a SQL injection, resulting in full database compromise. The injection point is the POST parameter 'pollid' in the module main_bigware_54.php.

Proof of concept is at: http://files.dw-itsecurity.de/54.zip

Time line:

01/23/2012: Vendor contacted
01/24/2012: Vendor response
04/16/2012: Vendor patch release
06/05/2012: Disclosure


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux