Geeklog Multiple Input Validation Vulnerabilities
BID:16755
Info
Geeklog Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 16755 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2006 12:00AM |
| Updated: | Feb 22 2006 11:22PM |
| Credit: | James Bercegay of the GulfTech Security Research Team is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Media Gallery Media Gallery 1.2.3 Geeklog Geeklog 1.3.11 sr3 Geeklog Geeklog 1.3.11 sr1 Geeklog Geeklog 1.3.11 rc1 Geeklog Geeklog 1.3.11 Geeklog Geeklog 1.3.10 Geeklog Geeklog 1.3.9 sr3 Geeklog Geeklog 1.3.9 sr2 Geeklog Geeklog 1.3.9 sr1 Geeklog Geeklog 1.3.9 Geeklog Geeklog 1.3.8 rc2 Geeklog Geeklog 1.3.8 rc1 Geeklog Geeklog 1.3.8 -1sr2 Geeklog Geeklog 1.3.8 -1sr1 Geeklog Geeklog 1.3.8 -1 Geeklog Geeklog 1.3.8 Geeklog Geeklog 1.3.7 sr2 Geeklog Geeklog 1.3.7 sr1 Geeklog Geeklog 1.3.7 Geeklog Geeklog 1.3.5 sr2 Geeklog Geeklog 1.3.5 sr1 Geeklog Geeklog 1.3.5 Geeklog Geeklog 1.3 |
| Not Vulnerable: |
Media Gallery Media Gallery 1.2.4 Geeklog Geeklog 1.4 sr1 Geeklog Geeklog 1.3.11 sr4 |
Discussion
Geeklog Multiple Input Validation Vulnerabilities
Geeklog is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Specifically, Geeklog is prone to:
- Multiple SQL-injection vulnerabilities
- An arbitrary local file-include vulnerability
Further information reports that Media Gallery is also vulnerable to these issues, because it shares the same code base.
Geeklog is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Specifically, Geeklog is prone to:
- Multiple SQL-injection vulnerabilities
- An arbitrary local file-include vulnerability
Further information reports that Media Gallery is also vulnerable to these issues, because it shares the same code base.
Exploit / POC
Geeklog Multiple Input Validation Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Geeklog Multiple Input Validation Vulnerabilities
Solution:
Geeklog and Media Gallery have released updates to address these issues.
Please see the referenced vendor advisories for details on obtaining and applying the appropriate updates.
Media Gallery Media Gallery 1.2.3
Geeklog Geeklog 1.3
Geeklog Geeklog 1.3.10
Geeklog Geeklog 1.3.11 sr3
Geeklog Geeklog 1.3.11
Geeklog Geeklog 1.3.11 rc1
Geeklog Geeklog 1.3.5
Geeklog Geeklog 1.3.5 sr2
Geeklog Geeklog 1.3.5 sr1
Geeklog Geeklog 1.3.7 sr2
Geeklog Geeklog 1.3.7
Geeklog Geeklog 1.3.7 sr1
Geeklog Geeklog 1.3.8 rc2
Geeklog Geeklog 1.3.8 -1
Geeklog Geeklog 1.3.8
Geeklog Geeklog 1.3.8 rc1
Geeklog Geeklog 1.3.8 -1sr2
Geeklog Geeklog 1.3.8 -1sr1
Geeklog Geeklog 1.3.9 sr2
Geeklog Geeklog 1.3.9 sr1
Geeklog Geeklog 1.3.9 sr3
Geeklog Geeklog 1.3.9
Solution:
Geeklog and Media Gallery have released updates to address these issues.
Please see the referenced vendor advisories for details on obtaining and applying the appropriate updates.
Media Gallery Media Gallery 1.2.3
-
Media Gallery Media Gallery 1.2.4
http://www.mediagallery.org/filemgmt/visit.php?lid=30
Geeklog Geeklog 1.3
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.10
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.11 sr3
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.11
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.11 rc1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.5
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.5 sr2
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.5 sr1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.7 sr2
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.7
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.7 sr1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.8 rc2
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.8 -1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.8
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.8 rc1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.8 -1sr2
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.8 -1sr1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.9 sr2
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.9 sr1
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.9 sr3
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
Geeklog Geeklog 1.3.9
-
Geeklog Geeklog 1.4.0sr1
http://www.geeklog.net/filemgmt/visit.php?lid=672
References
Geeklog Multiple Input Validation Vulnerabilities
References:
References:
- Geeklog Remote Code Execution (GulfTech Research)
- Geeklog 1.4.0sr1 and 1.3.11sr4 (Geeklog)
- Geeklog Homepage (Geeklog)
- Media Gallery Homepage (Media Gallery)
- Media Gallery v1.2.4 (Media Gallery)