This advisory is incorrect. The reported SQL injection vulnerability is not present within the version (4.3.3683.31484) of Iciniti Store claimed to be affected.
In addition, the legitimacy of the supplied proof of concept is questionable. The SQL statement shown would only be syntactically valid when injected and elicit a response containing the database version in the rarest of circumstances. It appears to have not been verified by Sense of Security. ICINITI Corporation has been contacted to comment on this advisory.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
