MaxWebPortal Events And Links Interface Multiple Input Validation Vulnerabilities
BID:12968
Info
MaxWebPortal Events And Links Interface Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 12968 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1016 CVE-2005-1017 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2005 12:00AM |
| Updated: | Jul 12 2009 11:56AM |
| Credit: | "Zinho" <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
MaxWebPortal MaxWebPortal 1.33 |
| Not Vulnerable: | |
Discussion
MaxWebPortal Events And Links Interface Multiple Input Validation Vulnerabilities
Multiple input validation vulnerabilities affect MaxWebPortal. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating dynamic Web content.
An attacker may exploit this issue to manipulate SQL queries to the underlying database and have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate theft of sensitive information, potentially including authentication credentials, and data corruption.
Multiple input validation vulnerabilities affect MaxWebPortal. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it to carry out critical application functionality such as database interaction and generating dynamic Web content.
An attacker may exploit this issue to manipulate SQL queries to the underlying database and have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate theft of sensitive information, potentially including authentication credentials, and data corruption.
Exploit / POC
MaxWebPortal Events And Links Interface Multiple Input Validation Vulnerabilities
No exploit is required to leverage these issues.
No exploit is required to leverage these issues.
Solution / Fix
MaxWebPortal Events And Links Interface Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MaxWebPortal Events And Links Interface Multiple Input Validation Vulnerabilities
References:
References:
- MaxWebPortal Homepage (MaxWebPortal)