search menu icon-carat-right cmu-wordmark

CERT Coordination Center

SkyPortal contains multiple SQL injection vulnerabilities

Vulnerability Note VU#315107

Original Release Date: 2008-06-11 | Last Revised: 2008-06-11

Overview

SkyPortal RC6 contains multiple SQL injection vulnerabilities which could allow a remote, unauthenticated attacker to gain access to the back-end database and to add, modify or remove data.

Description

SkyPortal is a modular web portal and online community system that includes web-based administration, user selectable skins, user control panel and additional modules such as Public Events Calendar, Classifieds Manager, WebLinks Manager, Download Manager, Article Manager, and Picture Manager.

There are multiple vulnerabilities in a number of pages and functions. These include nc_top.asp, inc_bookmarks.asp, inc_profile_functions.asp, inc_SUBSCRIPTIONS.asp, Avatar_URL, LINK1, and LINK2. Processing of maliciously crafted SQL commands to any of these functions could trigger the vulnerabilities.

Any web site developed with vulnerable versions of SkyPortal will (or is likely to) contain SQL injection vulnerabilities.

Impact

By sending specially crafted SQL statements to any of the stated functions, a remote, unauthenticated attacker could gain access to the system to add, modify or remove data. Attackers are using automated tools to inject malicious content into vulnerable sites.

Solution

This vulnerability was addressed in SkyPortal 1.0 and later.

Vendor Information

315107
 

SkyPortal Affected

Updated:  June 10, 2008

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

This vulnerability was addressed in SkyPortal 1.0 and later.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

The BugReport Security Research & Penetration Testing Group is credited with the discovery of these vulnerabilities.

This document was written by Joseph Pruszynski.

Other Information

CVE IDs: CVE-2007-6078
Severity Metric: 26.21
Date Public: 2007-11-21
Date First Published: 2008-06-11
Date Last Updated: 2008-06-11 18:21 UTC
Document Revision: 17

Sponsored by CISA.