ActivePost Messenger Multiple Remote Vulnerabilities
BID:11244
Info
ActivePost Messenger Multiple Remote Vulnerabilities
| Bugtraq ID: | 11244 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2004 12:00AM |
| Updated: | Sep 23 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
ActivePost Standard 3.1 ActivePost Standard 3.0 |
| Not Vulnerable: | |
Discussion
ActivePost Messenger Multiple Remote Vulnerabilities
ActivePost Messenger is reportedly affected by multiple remote vulnerabilities. These issues are due to a failure of the application to validate user-supplied input, a failure of the application to handle exceptional conditions, and a design error that fails to properly secure forum passwords.
The first issue is a denial of service issue. An attacker may cause the affected server to crash with malformed network data, denying service to legitimate users.
The second issue will allow an attacker to upload files to arbitrary locations writable by the affected server application.
The final issue is due to a design error that transmits plaintext forum passwords across the network.
ActivePost Messenger is reportedly affected by multiple remote vulnerabilities. These issues are due to a failure of the application to validate user-supplied input, a failure of the application to handle exceptional conditions, and a design error that fails to properly secure forum passwords.
The first issue is a denial of service issue. An attacker may cause the affected server to crash with malformed network data, denying service to legitimate users.
The second issue will allow an attacker to upload files to arbitrary locations writable by the affected server application.
The final issue is due to a design error that transmits plaintext forum passwords across the network.
Exploit / POC
ActivePost Messenger Multiple Remote Vulnerabilities
No exploit is required to leverage any of these issues. The following proof of concept code is available:
No exploit is required to leverage any of these issues. The following proof of concept code is available:
Solution / Fix
ActivePost Messenger Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ActivePost Messenger Multiple Remote Vulnerabilities
References:
References:
- ActivePost Standard Home Page (ActivePost)
- Multiple vulnerabilities in ActivePost Standard 3.1 (Luigi Auriemma
)