PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
BID:10258
Info
PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 10258 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2004 12:00AM |
| Updated: | May 01 2004 12:00AM |
| Credit: | Discovery is credited to Manuel Lopez <[email protected]>. |
| Vulnerable: |
PROPS PROPS 0.6.1 |
| Not Vulnerable: | |
Discussion
PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
It has been reported that PROPS is vulnerable to SQL injection and cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using the input in database queries. When a query fails, the error message, including the malicious content is displayed to the victim's browser.
These issues may allow an attacker to gain access to sensitive information, corrupt database contents, and steal authentication credentials. Other attacks are also possible.
It has been reported that PROPS is vulnerable to SQL injection and cross-site scripting vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using the input in database queries. When a query fails, the error message, including the malicious content is displayed to the victim's browser.
These issues may allow an attacker to gain access to sensitive information, corrupt database contents, and steal authentication credentials. Other attacks are also possible.
Exploit / POC
PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released an upgrade dealing with this issue.
PROPS PROPS 0.6.1
Solution:
The vendor has released an upgrade dealing with this issue.
PROPS PROPS 0.6.1
References
PROPS SQL Injection and Cross-Site Scripting Vulnerabilities
References:
References:
- Props 0.6.1 XSS and Remote File Viewing Vulnerability (Manuel Lopez
)