eTicket Multiple Scripts Multiple Input Validation Vulnerabilities
BID:27173
Info
eTicket Multiple Scripts Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27173 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0266 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | L4teral is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
eTicket eTicket 1.5.5.2 |
| Not Vulnerable: | |
Discussion
eTicket Multiple Scripts Multiple Input Validation Vulnerabilities
eTicket is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These vulnerabilities include multiple SQL-injection issues, a cross-site scripting issue, and an authentication-bypass issue.
A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user.
These issues affect eTicket 1.5.5.2; other versions may also be affected.
eTicket is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These vulnerabilities include multiple SQL-injection issues, a cross-site scripting issue, and an authentication-bypass issue.
A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user.
These issues affect eTicket 1.5.5.2; other versions may also be affected.
Exploit / POC
eTicket Multiple Scripts Multiple Input Validation Vulnerabilities
Attackers may exploit these issues through a browser.
To exploit the cross-site scripting or authentication-bypass issues, an attacker must entice an unsuspecting victim into visiting a malicious URI.
The following proof-of-concept code is available:
Attackers may exploit these issues through a browser.
To exploit the cross-site scripting or authentication-bypass issues, an attacker must entice an unsuspecting victim into visiting a malicious URI.
The following proof-of-concept code is available:
Solution / Fix
eTicket Multiple Scripts Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
eTicket Multiple Scripts Multiple Input Validation Vulnerabilities
References:
References:
- eTicket Homepage (eTicket)
- eTicket 1.5.5.2 Multiple Vulnerabilities (L4teral
)