EasyNews Multiple Input Validation Vulnerabilities
BID:28542
Info
EasyNews Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28542 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1651 CVE-2008-1649 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | IRCRASH |
| Vulnerable: |
MyioSoft EasyNews 4.0tr |
| Not Vulnerable: | |
Discussion
EasyNews Multiple Input Validation Vulnerabilities
EasyNews is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include SQL-injection, cross-site scripting, and local file-include vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, execute arbitrary local scripts, retrieve potentially sensitive information, or exploit latent vulnerabilities in the underlying database.
These issues affect EasyNews 4.0tr; other versions may also be vulnerable.
EasyNews is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include SQL-injection, cross-site scripting, and local file-include vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, execute arbitrary local scripts, retrieve potentially sensitive information, or exploit latent vulnerabilities in the underlying database.
These issues affect EasyNews 4.0tr; other versions may also be vulnerable.
Exploit / POC
EasyNews Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs and exploit code are available:
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs and exploit code are available:
Solution / Fix
EasyNews Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
EasyNews Multiple Input Validation Vulnerabilities
References:
References: