This application requires Javascript for optimal performance.

Fullaspsite.Asp.Hosting.SQL.Injection

Release Date

Mar 01, 2007

Severity

medium

Impact

The execution of arbitrary SQL commands on the system.

Description

It indicates a possible exploit of a SQL injection vulnerability in Fullaspsite Asp Hosting Sitesi.

This flaw is due to an input validation error in the "windows.asp" script that does not validate the "kategori_id" parameter before being used in SQL statements, which could be exploited by malicious users to conduct SQL injection attacks.

Affected Products

Fullaspsite Asp Hosting Sitesi.

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-0678

Reference/s

http://www.frsirt.com/english/advisories/2007/0453 (FrSIRT)
http://www.securityfocus.com/bid/22347 (BugTraq)

Reference: VID-14227