########################## www.BugReport.ir
#######################################
#
# AmnPardaz Security Research Team
#
# Title: Persia BME E-Catalogue SQL Injection Vulnerability
# Vendor: http://www.persiabme.com/products/
# Impact: High
# Fix: N/A
# Original Advisory: http://www.bugreport.ir/index_55.htm
###########################################################################
########
####################
1. Description:
####################
Persia BME E-Catalogue is a powerful engine which provides webmasters
with advanced abilities of controlling their website. The system has a free
style multi level Menu to add a company's products or services.
####################
2. Vulnerability:
####################
Input passed to the "q" parameter in "search.aspx" is not properly
sanitised before being used in SQL queries.
This can be exploited to manipulate SQL queries by injecting arbitrary SQL
code.
Its possible to obtain user's plain text password by this vulnerability.
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.