Site@School Multiple Input Validation Vulnerabilities
BID:20053
CVE-2006-4919 | CVE-2006-4920 | CVE-2006-4922 |Info
Site@School Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 20053 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2006 12:00AM |
| Updated: | Sep 18 2006 07:57PM |
| Credit: | simo64 is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Site@School Site@School 2.4.2 Site@School Site@School 2.4.1 Site@School Site@School 2.2.4 Site@School Site@School 2.3 |
| Not Vulnerable: |
Site@School Site@School 2.4.3 |
Discussion
Site@School Multiple Input Validation Vulnerabilities
Site@School is prone to multiple input-validation vulnerabilities, including an arbitrary-file-upload issue, multiple remote file-include issues, and a directory-traversal issue, because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to upload an arbitrary PHP file, execute the file on the vulnerable computer in the context of the webserver process, and retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may lead to other attacks.
Site@School 2.4.02 and earlier versions are vulnerable to these issues.
Site@School is prone to multiple input-validation vulnerabilities, including an arbitrary-file-upload issue, multiple remote file-include issues, and a directory-traversal issue, because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to upload an arbitrary PHP file, execute the file on the vulnerable computer in the context of the webserver process, and retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may lead to other attacks.
Site@School 2.4.02 and earlier versions are vulnerable to these issues.
Exploit / POC
Site@School Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available.
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available.
Solution / Fix
Site@School Multiple Input Validation Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
References
Site@School Multiple Input Validation Vulnerabilities
References:
References: