Envolution Multiple Input Validation Vulnerabilities
BID:15857
Info
Envolution Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15857 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2005 12:00AM |
| Updated: | Dec 14 2005 12:00AM |
| Credit: | Discovered by x1ng <[email protected]>. |
| Vulnerable: |
Envolution Envolution |
| Not Vulnerable: | |
Discussion
Envolution Multiple Input Validation Vulnerabilities
Envolution is prone to multiple input validation vulnerabilities.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
Envolution is prone to multiple input validation vulnerabilities.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
Exploit / POC
Envolution Multiple Input Validation Vulnerabilities
No exploit is required.
Proof of concept examples are available:
http://www.example.com/[envo]/modules.php?op=modload&name=News&file=index&catid=&topic=18&startrow=[sql] or [xss]
http://www.example.com/[envo]/modules.php?op=modload&name=News&file=index&catid=[sql] or [xss]
No exploit is required.
Proof of concept examples are available:
http://www.example.com/[envo]/modules.php?op=modload&name=News&file=index&catid=&topic=18&startrow=[sql] or [xss]
http://www.example.com/[envo]/modules.php?op=modload&name=News&file=index&catid=[sql] or [xss]
Solution / Fix
Envolution Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.