VCD-DB Multiple Input Validation Vulnerabilities
BID:15840
Info
VCD-DB Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15840 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2005 12:00AM |
| Updated: | Dec 13 2005 12:00AM |
| Credit: | rakstija r0t3d3Vil is credited with the discovery of this issue. |
| Vulnerable: |
VCD-db VCD-db 0.973 VCD-db VCD-db 0.972 VCD-db VCD-db 0.971 VCD-db VCD-db 0.961 VCD-db VCD-db 0.98 VCD-db VCD-db 0.97 |
| Not Vulnerable: | |
Discussion
VCD-DB Multiple Input Validation Vulnerabilities
VCD-db is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
VCD-db is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
Exploit / POC
VCD-DB Multiple Input Validation Vulnerabilities
No exploit is required.
An example URI sufficient to exploit the SQL injection issue:
http://www.example.com/search.php?searchstring=&by=[SQL]
An example URI sufficient to exploit the cross-site scripting issue:
http://www.example.com/?page=category&category_id=1&viewmode=img&batch=%22%3E%3Cscript%3Ealert('r0t')%3C/script%3E
No exploit is required.
An example URI sufficient to exploit the SQL injection issue:
http://www.example.com/search.php?searchstring=&by=[SQL]
An example URI sufficient to exploit the cross-site scripting issue:
http://www.example.com/?page=category&category_id=1&viewmode=img&batch=%22%3E%3Cscript%3Ealert('r0t')%3C/script%3E
Solution / Fix
VCD-DB Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
VCD-DB Multiple Input Validation Vulnerabilities
References:
References:
- VCD-db Home Page (VCD-db)
- VCD-db vuln. (rakstija r0t3d3Vil)