Absolute News Manager .NET Multiple Input Validation and Information Disclosure Vulnerabilities
BID:26692
Info
Absolute News Manager .NET Multiple Input Validation and Information Disclosure Vulnerabilities
| Bugtraq ID: | 26692 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6268 CVE-2007-6269 CVE-2007-6270 CVE-2007-6271 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2007 12:00AM |
| Updated: | Dec 12 2007 09:22PM |
| Credit: | Adrian Pastor, Jan Fry and Richard Brain of ProCheckUp Ltd. are credited with discovering these issues. |
| Vulnerable: |
XIGLA SOFTWARE Absolute News Manager .NET 5.1 |
| Not Vulnerable: | |
Discussion
Absolute News Manager .NET Multiple Input Validation and Information Disclosure Vulnerabilities
Absolute News Manager .NET is prone to multiple remote vulnerabilities, including multiple cross-site scripting, SQL-injection, and information-disclosure issues.
Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary script code in the context of the webserver process, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect Absolute News Manager .NET 5.1; other versions may also be vulnerable.
Absolute News Manager .NET is prone to multiple remote vulnerabilities, including multiple cross-site scripting, SQL-injection, and information-disclosure issues.
Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary script code in the context of the webserver process, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect Absolute News Manager .NET 5.1; other versions may also be vulnerable.
Exploit / POC
Absolute News Manager .NET Multiple Input Validation and Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Solution / Fix
Absolute News Manager .NET Multiple Input Validation and Information Disclosure Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
XIGLA SOFTWARE Absolute News Manager .NET 5.1
Solution:
The vendor released an update to address these issues. Please see the references for more information.
XIGLA SOFTWARE Absolute News Manager .NET 5.1
-
XIGLA SOFTWARE ANMNET51-SecurityUpdate20071128.zip
http://www.xigla.com/security/ANMNET51-SecurityUpdate20071128.zip
References
Absolute News Manager .NET Multiple Input Validation and Information Disclosure Vulnerabilities
References:
References: