CPaint xmlhttp Request Input Validation Vulnerability
BID:14577
Info
CPaint xmlhttp Request Input Validation Vulnerability
| Bugtraq ID: | 14577 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2005 12:00AM |
| Updated: | Aug 16 2005 12:00AM |
| Credit: | Discovery is credited to Thor Larholm <[email protected]>. |
| Vulnerable: |
CPAINT CPAINT 1.3 |
| Not Vulnerable: |
CPAINT CPAINT 1.3 -SP |
Discussion
CPaint xmlhttp Request Input Validation Vulnerability
CPAINT is prone to an input validation vulnerability. This issue occurs because the application fails to properly sanitize malicious scripts and requests from user-supplied input.
Successful exploitation of this vulnerability could lead to a compromise of the server running the affected application. Other attacks are also possible.
CPAINT is prone to an input validation vulnerability. This issue occurs because the application fails to properly sanitize malicious scripts and requests from user-supplied input.
Successful exploitation of this vulnerability could lead to a compromise of the server running the affected application. Other attacks are also possible.
Exploit / POC
CPaint xmlhttp Request Input Validation Vulnerability
No exploit code is required.
The following examples were provided:
calculator.asp?cpaint_function=addNumbers&cpaint_argument[]=1&cpaint_argument[]=2")%20%26%20eval("malicious code
http://someserver.com/cpaintfile.asp?cpaint_function=response.write&cpaint_argument[]=2")%20%26%20eval("malicious code
No exploit code is required.
The following examples were provided:
calculator.asp?cpaint_function=addNumbers&cpaint_argument[]=1&cpaint_argument[]=2")%20%26%20eval("malicious code
http://someserver.com/cpaintfile.asp?cpaint_function=response.write&cpaint_argument[]=2")%20%26%20eval("malicious code
Solution / Fix
CPaint xmlhttp Request Input Validation Vulnerability
Solution:
This vulnerability was reportedly fixed in the current release of the application. This has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This vulnerability was reportedly fixed in the current release of the application. This has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CPaint xmlhttp Request Input Validation Vulnerability
References:
References:
- CPAINT Homepage (CPAINT)
- RE: Vulnerability found in CPAINT Ajax Toolkit ("Thor Larholm"
)