[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201206051225.q55CPGFJ023290@sf01web3.securityfocus.com>
Date: Tue, 5 Jun 2012 12:25:16 GMT
From: rwenzel@...itsecurity.de
To: bugtraq@...urityfocus.com
Subject: SQL injection in Bigware shop software
The Bigware shop software prior to version 2.17 contains a SQL injection, resulting in full database compromise. The injection point is the POST parameter 'pollid' in the module main_bigware_54.php.
Proof of concept is at: http://files.dw-itsecurity.de/54.zip
Time line:
01/23/2012: Vendor contacted
01/24/2012: Vendor response
04/16/2012: Vendor patch release
06/05/2012: Disclosure
Powered by blists - more mailing lists