E-Publish Multiple Input Validation Vulnerabilities
BID:15964
Info
E-Publish Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15964 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | rakstija r0t3d3Vil discovered these issues. |
| Vulnerable: |
E-Publish E-Publish 2.0 |
| Not Vulnerable: | |
Discussion
E-Publish Multiple Input Validation Vulnerabilities
E-Publish is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
This issue reportedly affects version 2.0 of E-Publish; other versions may also be affected.
E-Publish is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.
This issue reportedly affects version 2.0 of E-Publish; other versions may also be affected.
Exploit / POC
E-Publish Multiple Input Validation Vulnerabilities
No exploit is required.
The following example URI are sufficient to demonstrate these issues:
http://www.example.com/printer_friendly.cfm?id=[SQL]
http://www.example.com/show.cfm?id=274&obcatid=10[XSS]
http://www.example.com/show.cfm?id=279&how=5&obcatid=9&shfrm=1&comid=[XSS]
No exploit is required.
The following example URI are sufficient to demonstrate these issues:
http://www.example.com/printer_friendly.cfm?id=[SQL]
http://www.example.com/show.cfm?id=274&obcatid=10[XSS]
http://www.example.com/show.cfm?id=279&how=5&obcatid=9&shfrm=1&comid=[XSS]
Solution / Fix
E-Publish Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
E-Publish Multiple Input Validation Vulnerabilities
References:
References:
- e-publish CMS vuln. (rakstija r0t3d3Vil)
- E-Publish Home Page (E-Publish)