Gallarific Cross Site Scripting, HTML Injection and Backdoor Vulnerabilities
BID:28794
Info
Gallarific Cross Site Scripting, HTML Injection and Backdoor Vulnerabilities
| Bugtraq ID: | 28794 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6567 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Thomas Pollet |
| Vulnerable: |
Gallarific Gallarific free version |
| Not Vulnerable: | |
Discussion
Gallarific Cross Site Scripting, HTML Injection and Backdoor Vulnerabilities
Gallarific is prone to multiple security vulnerabilities, including multiple HTML-injection issues and multiple cross-site scripting issues. In addition, the source code for the application's free version may have been compromised to include a malicious backdoor; this has not been confirmed.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user. Other attacks are also possible.
These issues affect the free versions of Gallarific; the paid version may also be vulnerable.
Gallarific is prone to multiple security vulnerabilities, including multiple HTML-injection issues and multiple cross-site scripting issues. In addition, the source code for the application's free version may have been compromised to include a malicious backdoor; this has not been confirmed.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user. Other attacks are also possible.
These issues affect the free versions of Gallarific; the paid version may also be vulnerable.
Exploit / POC
Gallarific Cross Site Scripting, HTML Injection and Backdoor Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Gallarific Cross Site Scripting, HTML Injection and Backdoor Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Gallarific Cross Site Scripting, HTML Injection and Backdoor Vulnerabilities
References:
References:
- gallarific backdoored , vulnerable to xss (Thomas Pollet)
- Gallarific Homepage (Gallarific)