Elastic Path Multiple Input Validation Vulnerabilities
BID:28352
Info
Elastic Path Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28352 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1606 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Daniel Martin Gomez of MWR InfoSecurity |
| Vulnerable: |
Elastic Path Software Elastic Path 4.1.1 Elastic Path Software Elastic Path 4.1 |
| Not Vulnerable: | |
Discussion
Elastic Path Multiple Input Validation Vulnerabilities
Elastic Path is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
These issues include:
- A local file-include vulnerability.
- An arbitrary file-upload vulnerability.
- A directory-traversal vulnerability.
Note that attackers must be logged into the application to exploit issues.
Exploiting these issues can allow attackers to access potentially sensitive information or to execute arbitrary script code in the context of the webserver process. Other attacks may also be possible.
Elastic Path 4.1 and 4.1.1 are vulnerable; other versions may also be affected.
Elastic Path is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input.
These issues include:
- A local file-include vulnerability.
- An arbitrary file-upload vulnerability.
- A directory-traversal vulnerability.
Note that attackers must be logged into the application to exploit issues.
Exploiting these issues can allow attackers to access potentially sensitive information or to execute arbitrary script code in the context of the webserver process. Other attacks may also be possible.
Elastic Path 4.1 and 4.1.1 are vulnerable; other versions may also be affected.
Exploit / POC
Elastic Path Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
Solution / Fix
Elastic Path Multiple Input Validation Vulnerabilities
Solution:
The vendor has released patches. Please contact the vendor for information on obtaining and applying the patches.
Solution:
The vendor has released patches. Please contact the vendor for information on obtaining and applying the patches.
References
Elastic Path Multiple Input Validation Vulnerabilities
References:
References:
- Elastic Path Homepage (Elastic Path Software)
- security advisory: Elastic Path Unrestricted Filesystem Access (etd�??s Dos and Dont�??s)