e107 Website System Multiple Input Validation and Information Disclosure Vulnerabilities
BID:13974
Info
e107 Website System Multiple Input Validation and Information Disclosure Vulnerabilities
| Bugtraq ID: | 13974 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2005 12:00AM |
| Updated: | Jun 16 2005 12:00AM |
| Credit: | Marc Ruef <[email protected]> is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
e107 e107 website system 0.617 e107 e107 website system 0.616 e107 e107 website system 0.6 15a e107 e107 website system 0.6 15 |
| Not Vulnerable: | |
Discussion
e107 Website System Multiple Input Validation and Information Disclosure Vulnerabilities
e107 Website System is prone to multiple input validation and information disclosure vulnerabilities.
The application has an information disclosure vulnerability regarding valid usernames.
The application is also vulnerable to several cross-site scripting and HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Some of the cross-site scripting issues are the same as described in BID 10436, which were believed to be addressed in previous versions of the application. Further information has reported that the application is still affected.
e107 Website System is prone to multiple input validation and information disclosure vulnerabilities.
The application has an information disclosure vulnerability regarding valid usernames.
The application is also vulnerable to several cross-site scripting and HTML injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.
Some of the cross-site scripting issues are the same as described in BID 10436, which were believed to be addressed in previous versions of the application. Further information has reported that the application is still affected.
Exploit / POC
e107 Website System Multiple Input Validation and Information Disclosure Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
e107 Website System Multiple Input Validation and Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
e107 Website System Multiple Input Validation and Information Disclosure Vulnerabilities
References:
References:
- e107 website system Homepage (e107.org)
- e107 v0.617 several new and old vulnerabilities (Marc Ruef
)