AbleDating 'search_results.php' Multiple Input Validation Vulnerabilities
BID:29342
Info
AbleDating 'search_results.php' Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 29342 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6439 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Ali Jasbi |
| Vulnerable: |
ABK-Soft AbleDating 2.4 |
| Not Vulnerable: | |
Discussion
AbleDating 'search_results.php' Multiple Input Validation Vulnerabilities
AbleDating is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include an SQL-injection vulnerability and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, execute arbitrary local scripts, retrieve potentially sensitive information, or exploit latent vulnerabilities in the underlying database.
These issues affect AbleDating 2.4; other versions may also be vulnerable.
AbleDating is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include an SQL-injection vulnerability and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, execute arbitrary local scripts, retrieve potentially sensitive information, or exploit latent vulnerabilities in the underlying database.
These issues affect AbleDating 2.4; other versions may also be vulnerable.
Exploit / POC
AbleDating 'search_results.php' Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
Solution / Fix
AbleDating 'search_results.php' Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AbleDating 'search_results.php' Multiple Input Validation Vulnerabilities
References:
References: