PBSite Multiple Input Validation Vulnerabilities
BID:28269
Info
PBSite Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28269 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2008 12:00AM |
| Updated: | Mar 18 2008 04:20PM |
| Credit: | Devil Auron |
| Vulnerable: |
PBSite PBSite Beta1 Core451 |
| Not Vulnerable: | |
Discussion
PBSite Multiple Input Validation Vulnerabilities
PBSite is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
These issues include a local file-include vulnerability and a vulnerability that allows attackers to alter cookie information so as to gain administrative access.
Exploiting these issues may allow an attacker to obtain potentially sensitive information and to run arbitrary local scripts in the context of the affected application.
PBSite is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
These issues include a local file-include vulnerability and a vulnerability that allows attackers to alter cookie information so as to gain administrative access.
Exploiting these issues may allow an attacker to obtain potentially sensitive information and to run arbitrary local scripts in the context of the affected application.
Exploit / POC
PBSite Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
PBSite Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].