Home page logo

bugtraq logo Bugtraq mailing list archives

SQL injection in Bigware shop software
From: rwenzel () dw-itsecurity de
Date: Tue, 5 Jun 2012 12:25:16 GMT

The Bigware shop software prior to version 2.17 contains a SQL injection, resulting in full database compromise. The 
injection point is the POST parameter 'pollid' in the module main_bigware_54.php.

Proof of concept is at: http://files.dw-itsecurity.de/54.zip

Time line:

01/23/2012: Vendor contacted
01/24/2012: Vendor response
04/16/2012: Vendor patch release
06/05/2012: Disclosure

  By Date           By Thread  

Current thread:
  • SQL injection in Bigware shop software rwenzel (Jun 05)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]