Project Logger Multiple Vulnerabilities
BID:11395
Info
Project Logger Multiple Vulnerabilities
| Bugtraq ID: | 11395 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2004 12:00AM |
| Updated: | Oct 06 2004 12:00AM |
| Credit: | These issues were reported by the vendor. |
| Vulnerable: |
Project Logger Project Logger 1.0 RC1 |
| Not Vulnerable: |
Project Logger Project Logger 1.0 RC2 |
Discussion
Project Logger Multiple Vulnerabilities
Project Logger is reported prone to multiple vulnerabilities.
It is reported that a remote attacker is able to corrupt data on a Web site by sending specially crafted HTTP POST requests to a server. The attacker is able to access and manipulate sensitive data by influencing the 'companyid' variable.
The vendor has specified another unspecified security vulnerability in settings. The cause and impact of this issue is currently unknown.
Project Logger is reported prone to multiple vulnerabilities.
It is reported that a remote attacker is able to corrupt data on a Web site by sending specially crafted HTTP POST requests to a server. The attacker is able to access and manipulate sensitive data by influencing the 'companyid' variable.
The vendor has specified another unspecified security vulnerability in settings. The cause and impact of this issue is currently unknown.
Exploit / POC
Project Logger Multiple Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Project Logger Multiple Vulnerabilities
Solution:
The vendor has released Project Logger 1.0RC2 to address these issues.
Project Logger Project Logger 1.0 RC1
Solution:
The vendor has released Project Logger 1.0RC2 to address these issues.
Project Logger Project Logger 1.0 RC1
-
Project Logger Project Logger 1.0RC2
http://sourceforge.net/project/showfiles.php?group_id=118438&package_i d=129063&release_id=273344