ESi WebEOC Multiple Input Validation Privilege Escalation and Denial of Service Vulnerabilities
BID:14249
Info
ESi WebEOC Multiple Input Validation Privilege Escalation and Denial of Service Vulnerabilities
| Bugtraq ID: | 14249 |
| Class: | Unknown |
| CVE: |
CVE-2005-2281 CVE-2005-2282 CVE-2005-2283 CVE-2005-2284 CVE-2005-2285 CVE-2005-2286 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | The vendor announced these vulnerabilities. |
| Vulnerable: |
ESi Products WebEOC 6.0.1 |
| Not Vulnerable: |
ESi Products WebEOC 6.0.2 |
Discussion
ESi WebEOC Multiple Input Validation Privilege Escalation and Denial of Service Vulnerabilities
WebEOC is affected by multiple vulnerabilities.
WebEOC is prone to multiple cross-site scripting, SQL injection, information disclosure, privilege escalation, access validation and denial of service vulnerabilities.
These issues are due to a series of input validation, access validation and other design errors in the application.
The vendor has addressed these issues in WebEOC version 6.0.2.
WebEOC is affected by multiple vulnerabilities.
WebEOC is prone to multiple cross-site scripting, SQL injection, information disclosure, privilege escalation, access validation and denial of service vulnerabilities.
These issues are due to a series of input validation, access validation and other design errors in the application.
The vendor has addressed these issues in WebEOC version 6.0.2.
Exploit / POC
ESi WebEOC Multiple Input Validation Privilege Escalation and Denial of Service Vulnerabilities
No exploits are required.
No exploits are required.
Solution / Fix
ESi WebEOC Multiple Input Validation Privilege Escalation and Denial of Service Vulnerabilities
Solution:
The vendor has addressed these issues in WebEOC version 6.0.2:
ESi Products WebEOC 6.0.1
Solution:
The vendor has addressed these issues in WebEOC version 6.0.2:
ESi Products WebEOC 6.0.1
-
ESi Products WebEOC 6.0.2
http://www.esi911.com/esi/products/webeoc.shtml
References
ESi WebEOC Multiple Input Validation Privilege Escalation and Denial of Service Vulnerabilities
References:
References:
- VU#138538 - WebEOC is vulnerable to cross-site scripting attacks (US-CERT)
- VU#165290 - WebEOC handles sensitive information in an insecure manner (US-CERT)
- VU#170394 - WebEOC account lock-out policy may allow a denial-of-service (US-CERT)
- VU#258834 - WebEOC privileges are based on client-side authorization (US-CERT)
- VU#372797 - WebEOC contains multiple SQL injection vulnerabilities (US-CERT)
- VU#388282 - WebEOC uses a global shared key (US-CERT)
- VU#491770 - WebEOC implements weak algorithms to encrypt sensitive information (US-CERT)
- VU#956762 - WebEOC is vulnerable to a denial-of-service condition via uploading (US-CERT)
- WebEOC Homepage (ESi Products)