Feedsplitter Multiple Input Validation Vulnerabilities
BID:19779
CVE-2006-4549 | CVE-2006-4550 | CVE-2006-4551 | CVE-2006-4552 |Info
Feedsplitter Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 19779 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2006 12:00AM |
| Updated: | Sep 21 2006 12:41AM |
| Credit: | Jonathan Rockway has been credited with the discovery of these vulnerabilities. |
| Vulnerable: |
CHXO Internet feedsplitter 2006-01-21 |
| Not Vulnerable: |
CHXO Internet feedsplitter 2006-09-19 |
Discussion
Feedsplitter Multiple Input Validation Vulnerabilities
Feedsplitter is prone to multiple input-validation vulnerabilities, including multiple arbitrary code-execution and HTML-injection vulnerabilities, an information-disclosure vulnerability, and a directory-traversal vulnerability.
An attacker can exploit these issues to retrieve arbitrary files from the vulnerable system, to execute arbitrary code in the context of the affected webserver, to retrieve sensitive information, to steal cookie-based authentication credentials, and to control how the site is rendered to the user. Other attacks are also possible.
Versions 2006-01-21 and prior are vulnerable.
Feedsplitter is prone to multiple input-validation vulnerabilities, including multiple arbitrary code-execution and HTML-injection vulnerabilities, an information-disclosure vulnerability, and a directory-traversal vulnerability.
An attacker can exploit these issues to retrieve arbitrary files from the vulnerable system, to execute arbitrary code in the context of the affected webserver, to retrieve sensitive information, to steal cookie-based authentication credentials, and to control how the site is rendered to the user. Other attacks are also possible.
Versions 2006-01-21 and prior are vulnerable.
Exploit / POC
Feedsplitter Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
Feedsplitter Multiple Input Validation Vulnerabilities
Solution:
The vendor has released version 2006-09-19 to address this issue.
Please see the references section for more information.
CHXO Internet feedsplitter 2006-01-21
Solution:
The vendor has released version 2006-09-19 to address this issue.
Please see the references section for more information.
CHXO Internet feedsplitter 2006-01-21
-
CHXO Internet Feedsplitter 2006-09-19
http://chxo.com/source/feedsplitter-2006-09-19.tar.gz
References
Feedsplitter Multiple Input Validation Vulnerabilities
References:
References:
- Feedsplitter Home Page (CXHO Internet)
- Mandatory Upgrade: Feedsplitter 2006-09-19 (Chris Snyder CXHO Internet)
- feedsplitter considered harmful ([email protected])