|
|
|
![]() |
Vulnerability Note VU#925166PhpWebSite calendar module contains a SQL injection vulnerabilityOverviewThe PhpWebSite contains an SQL injection vulnerability that may allow malicious users to execute SQL queries on a server with the privileges of the PhpWebSite administrator.I. DescriptionPhpWebSite is an open-source web content management system that includes a web-based calendar module to let users to create, post, and view events on a PhpWebSite managed site. By default users must have requests for new events approved by a site administrator before they are added to the calendar. However, lack of input validation of the cal_template variable may allow malicious users to inject a SQL query into the new event. If a site administrator approves the event the SQL query will be executed.II. ImpactA remote attacker may be able to execute SQL queries on a server with the privileges of a PhpWebSite administrator.III. SolutionApply a PatchPhpWebsite has released a patch to address this issue available at: http://www.phpwebsite.appstate.edu/downloads/security/phpwebsite-core-security-patch.tar.gz.
References
This vulnerability was publicly reported by GulfTech Security. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||