what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Batavi 1.1.2 SQL Injection

Batavi 1.1.2 SQL Injection
Posted Feb 7, 2012
Authored by Onur YILMAZ | Site netsparker.com

Batavi version 1.1.2 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | 6fc8dda996f6e7a4e9f86390ea2fa22440cde5c58ca16e649410cff0a2c7a070

Batavi 1.1.2 SQL Injection

Change Mirror Download
Information
--------------------
Name :  SQL Injection Vulnerability in Batavi
Software :  Batavi 1.1.2 and possibly below.
Vendor Homepage :  https://www.batavi.org
Vulnerability Type :  SQL Injection
Severity :  Critical
Researcher :  Onur Yılmaz
Advisory Reference :  NS-12-003

Description
--------------------
Batavi is an open source e-commerce platform.

Details
--------------------
Batavi is affected by a SQL Injection vulnerability in version 1.1.2..
Example PoC url is as follows :

https://example.com/ajax.php (POST - Param: boxToReload)


Solution
--------------------
The vendor fixed this vulnerability in the new version. Please see the
references.


Advisory Timeline
--------------------
05/12/2011 - First contact: Sent the vulnerability details
19/12/2011 - Second contact: Ask for patch
18/01/2012 - Vulnerability Fixed in latest version
24/01/2012 - Vulnerability Released

Credits
--------------------
It has been discovered on testing of Netsparker, Web Application
Security Scanner.

References
--------------------
Vendor Url / Patch : https://sourceforge.net/projects/batavi/files/
MSL Advisory Link :
https://www.mavitunasecurity.com/sql-injection-vulnerability-in-batavi-ecommerce/
Netsparker Advisories : https://www.mavitunasecurity.com/netsparker-advisories/

About Netsparker
--------------------
Netsparker® can find and report security issues such as SQL Injection
and Cross-site Scripting (XSS) in all web applications regardless of
the platform and the technology they are built on. Netsparker's unique
detection and exploitation techniques allows it to be dead accurate in
reporting hence it's the first and the only False Positive Free web
application security scanner.

--
Netsparker Advisories, <advisories@mavitunasecurity.com>
Homepage, https://www.mavitunasecurity.com/netsparker-advisories/
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close