Key Information Vulnerability Description - Vulnerability Name: ParsaWeb CMS - 'Search' SQL Injection - EID-ID: 6610 - CVE ID: 2008-4364 - Vulnerability Type: SQL Injection - Authentication Status: EDB Verified Vulnerability Details - Affected Platform: ASP.net - Date: 2008-09-28 - Publisher: BUGREPORT.IR - Category: webapps Vulnerability Description - Product Information: ParsaWeb is a commercial ASP.NET website and content management system. - Vulnerability Details: Input received by in and the search section is not properly sanitized before being used in SQL queries, allowing attackers to inject arbitrary SQL code. Exploitation Examples - - Mitigation - Modify the source code to ensure proper sanitization of user input. Acknowledgments - Discoverer: AnnPardaz Security Research & Penetration Testing Group - Contact: admin[@]bugreport[d0t]ir