SQLiteWebAdmin Multiple Input Validation Vulnerabilities
BID:19253
Info
SQLiteWebAdmin Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 19253 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4102 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2006 12:00AM |
| Updated: | Jul 05 2016 09:25PM |
| Credit: | Sirdarckcat is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
projektfarm GmbH SQLiteWebAdmin 0.1 |
| Not Vulnerable: | |
Discussion
SQLiteWebAdmin Multiple Input Validation Vulnerabilities
SQLiteWebAdmin is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These issues include:
- A remote file-include vulnerability. A remote attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process.
- An SQL-injection vulnerability. A remote attacker can exploit this issue to access or modify data or to exploit vulnerabilities in the underlying database implementation.
- Multiple vulnerabilities affecting the HTTP response header. A remote attacker can exploit these issues to influence or misrepresent how web content is served.
SQLiteWebAdmin is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These issues include:
- A remote file-include vulnerability. A remote attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process.
- An SQL-injection vulnerability. A remote attacker can exploit this issue to access or modify data or to exploit vulnerabilities in the underlying database implementation.
- Multiple vulnerabilities affecting the HTTP response header. A remote attacker can exploit these issues to influence or misrepresent how web content is served.
Exploit / POC
SQLiteWebAdmin Multiple Input Validation Vulnerabilities
Attackers can exploit these issues through a web-client.
The following proof of concept URIs are available:
Attackers can exploit these issues through a web-client.
The following proof of concept URIs are available:
Solution / Fix
SQLiteWebAdmin Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SQLiteWebAdmin Multiple Input Validation Vulnerabilities
References:
References:
- SQLiteWebAdmin Home Page (projektfarm GmbH)