ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities
BID:24616
Info
ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 24616 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2007 12:00AM |
| Updated: | Jun 25 2007 10:38PM |
| Credit: | r0r is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ClickTech ClickGallery Server 5.1 |
| Not Vulnerable: | |
Discussion
ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities
ClickGallery Server is prone to multiple input-validation vulnerabilities, including an SQL-injection issue and a cross-site scripting issue, because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ClickGallery Server 5.1 and prior versions are vulnerable.
ClickGallery Server is prone to multiple input-validation vulnerabilities, including an SQL-injection issue and a cross-site scripting issue, because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ClickGallery Server 5.1 and prior versions are vulnerable.
Exploit / POC
ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim user to follow a malicious URI.
Solution / Fix
ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
ClickGallery Server Edit_Image.ASP Multiple Input Validation Vulnerabilities
References:
References:
- Vendor Homepage (ClickTech)