Bitweaver Multiple Input Validation Vulnerabilities
BID:15962
Info
Bitweaver Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15962 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | r0t is credited with the discovery of this vulnerability. |
| Vulnerable: |
Bitweaver Bitweaver 1.1.1 beta |
| Not Vulnerable: |
Bitweaver Bitweaver 1.2 |
Discussion
Bitweaver Multiple Input Validation Vulnerabilities
bitweaver is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
bitweaver 1.1.1 beta and prior are vulnerable; other versions may also be affected.
bitweaver is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
bitweaver 1.1.1 beta and prior are vulnerable; other versions may also be affected.
Exploit / POC
Bitweaver Multiple Input Validation Vulnerabilities
No exploit is required.
Example URI have been provided:
http://www.example.com/fisheye/list_galleries.php?sort_mode=[SQL]
http://www.example.com/blogs/view_post.php?post_id=[SQL]
http://www.example.com/blogs/view.php?blog_id=[SQL]
http://www.example.com/messages/message_box.php?sort_mode=[SQL]
http://www.example.com/users/my.php?sort_mode=[SQL]
No exploit is required.
Example URI have been provided:
http://www.example.com/fisheye/list_galleries.php?sort_mode=[SQL]
http://www.example.com/blogs/view_post.php?post_id=[SQL]
http://www.example.com/blogs/view.php?blog_id=[SQL]
http://www.example.com/messages/message_box.php?sort_mode=[SQL]
http://www.example.com/users/my.php?sort_mode=[SQL]
Solution / Fix
Bitweaver Multiple Input Validation Vulnerabilities
Solution:
The vendor has released version 1.2 addressing these issues:
Bitweaver Bitweaver 1.1.1 beta
Solution:
The vendor has released version 1.2 addressing these issues:
Bitweaver Bitweaver 1.1.1 beta
-
Bitweaver bitweaver_1.2.0.tar.gz
http://prdownloads.sourceforge.net/bitweaver/bitweaver_1.2.0.tar.gz
References
Bitweaver Multiple Input Validation Vulnerabilities
References:
References:
- Bitweaver Homepage (bitweaver)
- bitweaver multiple vuln. (r0t)
- bitweaver version 1.2 released (bitweaver)