P4DB Multiple Input Validation Vulnerabilities
BID:10286
Info
P4DB Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 10286 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2004 12:00AM |
| Updated: | May 05 2004 12:00AM |
| Credit: | Disclosure of these issues is credited to Jon McClintock <[email protected]>. |
| Vulnerable: |
P4DB Repository Web Interface 2.0 1 P4DB Repository Web Interface 2.0 P4DB Repository Web Interface 0.99 h-2 |
| Not Vulnerable: | |
Discussion
P4DB Multiple Input Validation Vulnerabilities
It has been reported that P4DB is affected by multiple input validation vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
Both cross-site scripting and remote, arbitrary command execution vulnerabilities have been reported.
The cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
Exploitation of the command execution vulnerabilities could allow a remote, unauthenticated user to remotely execute arbitrary commands on the underlying system with the privileges of the web server that is hosting the vulnerable application.
Currently the information available is not sufficient to provide more information; this BID will be updated as new details are released.
It has been reported that P4DB is affected by multiple input validation vulnerabilities. These issues are due to a failure of the application to properly sanitize user-supplied URI input.
Both cross-site scripting and remote, arbitrary command execution vulnerabilities have been reported.
The cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.
Exploitation of the command execution vulnerabilities could allow a remote, unauthenticated user to remotely execute arbitrary commands on the underlying system with the privileges of the web server that is hosting the vulnerable application.
Currently the information available is not sufficient to provide more information; this BID will be updated as new details are released.
Exploit / POC
P4DB Multiple Input Validation Vulnerabilities
No exploit is required to leverage these issues.
No exploit is required to leverage these issues.
Solution / Fix
P4DB Multiple Input Validation Vulnerabilities
Solution:
It has been reported that the developer of this software has discontinued support for this application.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that the developer of this software has discontinued support for this application.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
P4DB Multiple Input Validation Vulnerabilities
References:
References:
- Product Home Page (P4DB)
- Multiple vulnerabilities in P4DB (Jon McClintock
)