LightNEasy Multiple Input Validation Vulnerabilities
BID:28801
Info
LightNEasy Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28801 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6592 CVE-2008-6593 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2008 12:00AM |
| Updated: | Jun 12 2009 06:29PM |
| Credit: | girex |
| Vulnerable: |
LightNEasy LightNEasy 1.2.2 |
| Not Vulnerable: | |
Discussion
LightNEasy Multiple Input Validation Vulnerabilities
LightNEasy is prone to multiple vulnerabilities, including SQL-injection, security-bypass, and information-disclosure issues, because it fails to sufficiently sanitize user-supplied data.
Successful exploits of these vulnerabilities may allow attackers to:
- compromise the application
- access or modify data
- exploit latent vulnerabilities in the underlying database
- view files and execute local scripts in the context of the webserver process
- execute arbitrary PHP script code in the context of the webserver process
These issues affect LightNEasy 1.2.2 and prior versions.
LightNEasy is prone to multiple vulnerabilities, including SQL-injection, security-bypass, and information-disclosure issues, because it fails to sufficiently sanitize user-supplied data.
Successful exploits of these vulnerabilities may allow attackers to:
- compromise the application
- access or modify data
- exploit latent vulnerabilities in the underlying database
- view files and execute local scripts in the context of the webserver process
- execute arbitrary PHP script code in the context of the webserver process
These issues affect LightNEasy 1.2.2 and prior versions.
Exploit / POC
LightNEasy Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit this issue.
The following proofs of concept are available:
Attackers can use a browser to exploit this issue.
The following proofs of concept are available:
Solution / Fix
LightNEasy Multiple Input Validation Vulnerabilities
Solution:
The vendor has released a patch. Please see the references for more information.
LightNEasy LightNEasy 1.2.2
Solution:
The vendor has released a patch. Please see the references for more information.
LightNEasy LightNEasy 1.2.2
-
LightNEasy LightNEasy 1.2.2 no database_patch
http://www.lightneasy.org/downloads.php?dlid=57