Xtreme Topsites Multiple Input Validation Vulnerabilities
BID:18055
CVE-2006-2543 | CVE-2006-2545 |Info
Xtreme Topsites Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 18055 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2006 12:00AM |
| Updated: | May 23 2006 06:23PM |
| Credit: | Luny is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Xtreme Scripts Xtreme Topsites 1.1 |
| Not Vulnerable: | |
Discussion
Xtreme Topsites Multiple Input Validation Vulnerabilities
Xtreme Topsites is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting, HTML-injection, and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Xtreme Topsites is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting, HTML-injection, and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
Exploit / POC
Xtreme Topsites Multiple Input Validation Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
Xtreme Topsites Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Xtreme Topsites Multiple Input Validation Vulnerabilities
References:
References:
- Xtreme Topsites Homepage (Xtreme Scripts)
- Xtremescripts Topsites v1.1 (luny)