Easypx41 Multiple Variable Injection Vulnerabilities
BID:14421
Info
Easypx41 Multiple Variable Injection Vulnerabilities
| Bugtraq ID: | 14421 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2005 12:00AM |
| Updated: | Jul 29 2005 12:00AM |
| Credit: | FalconDeOro <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Easy PX 41 CMS 1.0 TEST Easy PX 41 CMS 1.0 FULL |
| Not Vulnerable: | |
Discussion
Easypx41 Multiple Variable Injection Vulnerabilities
Easypx41 is prone to multiple variable injection vulnerabilities.
An attacker can manipulate multiple script input variables and bypass access controls to retrieve sensitive and privileged information. Information obtained may aid in further attacks against the vulnerable application or the underlying system.
Easypx41 is prone to multiple variable injection vulnerabilities.
An attacker can manipulate multiple script input variables and bypass access controls to retrieve sensitive and privileged information. Information obtained may aid in further attacks against the vulnerable application or the underlying system.
Exploit / POC
Easypx41 Multiple Variable Injection Vulnerabilities
No exploit is required.
Examples of information disclosure have been provided:
http://www.example.com/index.php?pg=&L=[variable-injection]&H=[variable-injection]
http://www.example.com/index.php?pg=modules/forum/viewtopic.php&Forum=Forum%20de%20d?monstration.&msg=1103495330.dat&pgfull[variable-injection]
http://www.example.com/index.php?pg=http://google.fr&pgtype=iframe&amp;amp;L=500&H=500
http://www.example.com/index.php?pg=modules/forum/viewprofil.php&membres=[variable-injection]&pgfull[variable-injection]
http://www.example.com/index.php?pg=modules/forum/viewprofil.php&membres=[variable-injection]
http://www.example.com/index.php?pg=modules/forum/viewtopic.php&Forum=[change-or-variable-injection].&msg=1103495330.dat&pgfull
No exploit is required.
Examples of information disclosure have been provided:
http://www.example.com/index.php?pg=&L=[variable-injection]&H=[variable-injection]
http://www.example.com/index.php?pg=modules/forum/viewtopic.php&Forum=Forum%20de%20d?monstration.&msg=1103495330.dat&pgfull[variable-injection]
http://www.example.com/index.php?pg=http://google.fr&pgtype=iframe&amp;amp;L=500&H=500
http://www.example.com/index.php?pg=modules/forum/viewprofil.php&membres=[variable-injection]&pgfull[variable-injection]
http://www.example.com/index.php?pg=modules/forum/viewprofil.php&membres=[variable-injection]
http://www.example.com/index.php?pg=modules/forum/viewtopic.php&Forum=[change-or-variable-injection].&msg=1103495330.dat&pgfull
Solution / Fix
Easypx41 Multiple Variable Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.