CandyPress Multiple Input Validation Vulnerabilities
BID:27454
Info
CandyPress Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27454 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0736 CVE-2008-0546 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2008 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | AmnPardaz Security Research & Penetration Testing Group is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ShoppingTree CandyPress Store 4.1.1.26 ShoppingTree CandyPress Store 4.1 |
| Not Vulnerable: |
ShoppingTree CandyPress Store 4.1.1.27 |
Discussion
CandyPress Multiple Input Validation Vulnerabilities
CandyPress is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These issues include multiple SQL-injection vulnerabilities and a cross-site scripting vulnerability.
A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user.
These issues affect CandyPress 4.1.1.26; other versions may also be affected.
CandyPress is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input. These issues include multiple SQL-injection vulnerabilities and a cross-site scripting vulnerability.
A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user.
These issues affect CandyPress 4.1.1.26; other versions may also be affected.
Exploit / POC
Solution / Fix
References
CandyPress Multiple Input Validation Vulnerabilities
References:
References: