PSY Auction Multiple Input Validation Vulnerabilities
BID:17974
Info
PSY Auction Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 17974 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2006 12:00AM |
| Updated: | May 16 2006 09:14PM |
| Credit: | Luny is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
PHP Script Tools PSY Auction 0 |
| Not Vulnerable: | |
Discussion
PSY Auction Multiple Input Validation Vulnerabilities
PSY Auction is prone to multiple input-validation vulnerabilities. The issues include HTML-injection and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
PSY Auction is prone to multiple input-validation vulnerabilities. The issues include HTML-injection and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Exploit / POC
PSY Auction Multiple Input Validation Vulnerabilities
These issues can be exploited through a web client.
The following proof-of-concept URIs are available:
These issues can be exploited through a web client.
The following proof-of-concept URIs are available:
Solution / Fix
PSY Auction Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
PSY Auction Multiple Input Validation Vulnerabilities
References:
References:
- PHP Script Yard Homepage (PHP Script Tools)