YeiZea

SQL Injection Vulnerability in Batavi

Apr 27th, 2013
178
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.92 KB | None | 0 0
  1.  
  2.  
  3. Information
  4. --------------------
  5. Name : SQL Injection Vulnerability in Batavi
  6. Software : Batavi 1.1.2 and possibly below.
  7. Vendor Homepage : http://www.batavi.org
  8. Vulnerability Type : SQL Injection
  9. Severity : Critical
  10. Researcher : Onur Yılmaz
  11. Advisory Reference : NS-12-003
  12.  
  13. Description
  14. --------------------
  15. Batavi is an open source e-commerce platform.
  16.  
  17. Details
  18. --------------------
  19. Batavi is affected by a SQL Injection vulnerability in version 1.1.2..
  20. Example PoC url is as follows :
  21.  
  22. http://example.com/ajax.php (POST - Param: boxToReload)
  23. Solution
  24. --------------------
  25. The vendor fixed this vulnerability in the new version. Please see the references.
  26.  
  27. Advisory Timeline
  28. --------------------
  29. 05/12/2011 - First contact: Sent the vulnerability details
  30. 19/12/2011 - Second contact: Ask for patch
  31. 18/01/2012 - Vulnerability Fixed in latest version
  32. 24/01/2012 - Vulnerability Released
Advertisement
Add Comment
Please, Sign In to add comment