Numara FootPrints HTML Injection and Remote Command Execution Vulnerabilities
BID:28103
Info
Numara FootPrints HTML Injection and Remote Command Execution Vulnerabilities
| Bugtraq ID: | 28103 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1213 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Ricky Zhou and an anonymous researcher are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Numara FootPrints 8.1 |
| Not Vulnerable: | |
Discussion
Numara FootPrints HTML Injection and Remote Command Execution Vulnerabilities
Numara FootPrints is prone to an HTML-injection vulnerability and a remote command-execution vulnerability because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary commands within the context of the webserver, execute arbitrary HTML or JavaScript code within the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user. Other attacks are also possible.
Numara FootPrints 8.1 for Linux is vulnerable; other versions running on different platforms may also be affected.
Numara FootPrints is prone to an HTML-injection vulnerability and a remote command-execution vulnerability because the application fails to sufficiently sanitize user-supplied input.
Attackers can exploit these issues to execute arbitrary commands within the context of the webserver, execute arbitrary HTML or JavaScript code within the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user. Other attacks are also possible.
Numara FootPrints 8.1 for Linux is vulnerable; other versions running on different platforms may also be affected.
Exploit / POC
Numara FootPrints HTML Injection and Remote Command Execution Vulnerabilities
An attacker can use a browser to exploit these issues.
An attacker can use a browser to exploit these issues.
Solution / Fix
Numara FootPrints HTML Injection and Remote Command Execution Vulnerabilities
Solution:
Vendor patches are available. Please contact the vendor for more information.
Numara FootPrints 8.1
Solution:
Vendor patches are available. Please contact the vendor for more information.
Numara FootPrints 8.1
-
Numara patch_2008-03-28_81_92594_security_fixes.zip
http://support.unipress.com/MRcgi/MRdownloadAttachment.pl/patch_2008-0 3-28_81_92594_security_fixes.zip?USER=&PROJECTID=4&MRP=0&EXT_LINK=&CUS TM=&SOLUTIONS_FROM_OTHER_PROJ=&ORIGINAL_PROJECT=&MR=93860&ATTACHMENT_N AME=patch_2008-03-28_81_92594_security_fixes.zip
References
Numara FootPrints HTML Injection and Remote Command Execution Vulnerabilities
References:
References:
- Numara Homepage (Numara)
- Public Knowledge Base Solution 93860 -- General Information (Numara)