LiveCMS Multiple Input Validation Vulnerabilities
BID:24580
Info
LiveCMS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24580 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3292 CVE-2007-3290 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Vipsta and Clorox are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
LiveCMS LiveCMS 3.4 |
| Not Vulnerable: | |
Discussion
LiveCMS Multiple Input Validation Vulnerabilities
LiveCMS is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input. These issues include an SQL-injection vulnerability, an HTML-injection issue, and an arbitrary-file-upload vulnerability.
A successful exploit may allow an attacker to steal cookie-based authentication credentials, execute malicious script code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
LiveCMS 3.4 and prior versions are reported vulnerable to these issues.
LiveCMS is prone to multiple input-validation vulnerabilities because the application fails to sanitize user-supplied input. These issues include an SQL-injection vulnerability, an HTML-injection issue, and an arbitrary-file-upload vulnerability.
A successful exploit may allow an attacker to steal cookie-based authentication credentials, execute malicious script code, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
LiveCMS 3.4 and prior versions are reported vulnerable to these issues.
Exploit / POC
LiveCMS Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploit code is available:
Attackers can use a browser to exploit these issues.
The following exploit code is available:
Solution / Fix
LiveCMS Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].