SiteBar Multiple Input Validation Vulnerabilities
BID:26126
CVE-2006-3320 |Info
SiteBar Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 26126 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5491 CVE-2007-5492 CVE-2007-5692 CVE-2007-5693 CVE-2007-5694 CVE-2007-5695 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2007 12:00AM |
| Updated: | Dec 18 2007 08:04PM |
| Credit: | Robert Buchholz of Gentoo and Tim Brown are credited with the discovery of these issues. |
| Vulnerable: |
SiteBar SiteBar 3.3.8 SiteBar SiteBar 3.3.7 SiteBar SiteBar 3.3.6 SiteBar SiteBar 3.3.5 SiteBar SiteBar 3.3.4 SiteBar SiteBar 3.3.3 SiteBar SiteBar 3.3.2 SiteBar SiteBar 3.2.6 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha |
| Not Vulnerable: |
SiteBar SiteBar 3.3.9 |
Discussion
SiteBar Multiple Input Validation Vulnerabilities
SiteBar is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
These issues include:
- A local file-include vulnerability
- Multiple arbitrary-script-code-execution vulnerabilities
- Multiple cross-site scripting vulnerabilities
- A URI-redirection vulnerability.
Exploiting these issues can allow attackers to access potentially sensitive information, to execute arbitrary script code in the context of the webserver process, to steal cookie-based authentication credentials, and to redirect users to malicious webpages.
SiteBar 3.3.8 and prior versions are vulnerable.
SiteBar is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
These issues include:
- A local file-include vulnerability
- Multiple arbitrary-script-code-execution vulnerabilities
- Multiple cross-site scripting vulnerabilities
- A URI-redirection vulnerability.
Exploiting these issues can allow attackers to access potentially sensitive information, to execute arbitrary script code in the context of the webserver process, to steal cookie-based authentication credentials, and to redirect users to malicious webpages.
SiteBar 3.3.8 and prior versions are vulnerable.
Exploit / POC
SiteBar Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
Solution / Fix
SiteBar Multiple Input Validation Vulnerabilities
Solution:
The vendor released SiteBar 3.3.9 to address these issues. Please see the references for more information.
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Debian Linux 4.0 arm
Debian Linux 4.0 hppa
Debian Linux 4.0 sparc
Debian Linux 4.0 s/390
Debian Linux 4.0 powerpc
Debian Linux 4.0 alpha
Debian Linux 4.0 m68k
Debian Linux 4.0 mipsel
Debian Linux 4.0 ia-64
Debian Linux 4.0 mips
Debian Linux 3.1 ppc
Debian Linux 3.1 ia-64
Debian Linux 3.1 arm
Debian Linux 3.1 mips
Debian Linux 3.1 ia-32
Debian Linux 3.1 alpha
Debian Linux 3.1 m68k
Debian Linux 3.1 mipsel
Debian Linux 3.1 s/390
Debian Linux 3.1 amd64
Debian Linux 3.1 hppa
Debian Linux 3.1 sparc
SiteBar SiteBar 3.2.6
SiteBar SiteBar 3.3.2
SiteBar SiteBar 3.3.3
SiteBar SiteBar 3.3.4
SiteBar SiteBar 3.3.5
SiteBar SiteBar 3.3.6
SiteBar SiteBar 3.3.7
SiteBar SiteBar 3.3.8
Solution:
The vendor released SiteBar 3.3.9 to address these issues. Please see the references for more information.
Debian Linux 4.0 amd64
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 ia-32
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 arm
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 hppa
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 sparc
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 s/390
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 powerpc
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 alpha
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 m68k
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 mipsel
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 ia-64
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 4.0 mips
-
Debian sitebar_3.3.8-7etch1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.3.8-7 etch1_all.deb
Debian Linux 3.1 ppc
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 ia-64
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 arm
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 mips
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 ia-32
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 alpha
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 m68k
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 mipsel
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 s/390
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 amd64
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 hppa
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
Debian Linux 3.1 sparc
-
Debian sitebar_3.2.6-7.1sarge1_all.deb
http://security.debian.org/pool/updates/main/s/sitebar/sitebar_3.2.6-7 .1sarge1_all.deb
SiteBar SiteBar 3.2.6
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.2
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.3
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.4
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.5
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.6
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.7
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
SiteBar SiteBar 3.3.8
-
SiteBar SiteBar-3.3.9.tar.bz2
http://downloads.sourceforge.net/sitebar/SiteBar-3.3.9.tar.bz2?modtime =1192322139&big_mirror=0
References
SiteBar Multiple Input Validation Vulnerabilities
References:
References:
- 3.3.9 Release Notes (SiteBar)
- SiteBar Home Page (SiteBar)
- Serious holes affecting SiteBar 3.3.8 (Tim Brown
)