OSVDB ID: 30250

Title: abarcar Realty Portal slistl.php slid Parameter SQL Injection

Info

Disclosure

Nov 08, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

abarcar Realty Portal has been reported to contain a flaw that may allow an attacker to carry out an SQL injection attack. The issue is supposedly due to the slistl.php script not properly sanitizing user-supplied input to the 'slid' variable. However, the vendor reports that this script never existed in any version of the product.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure, Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
OSVDB: Web Related, Myth / Fake

Solution

The vulnerability reported is incorrect. No solution required.

Products

abarcar

Realty Portal

6

References

Credit

  • Benjamin Mossé - saps.auditgmail.com - Security Access Point
  • laurent gaffie - laurent.gaffiegmail.com -


Direct URL: http://osvdb.org/30250