QuickerSite Multiple Vulnerabilities
BID:29524
Info
QuickerSite Multiple Vulnerabilities
| Bugtraq ID: | 29524 |
| Class: | Unknown |
| CVE: |
CVE-2008-6673 CVE-2008-6674 CVE-2008-6675 CVE-2008-6676 CVE-2008-6677 CVE-2008-6678 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | AmnPardaz Security Research Team |
| Vulnerable: |
QuickerSite QuickerSite 1.8.5 |
| Not Vulnerable: | |
Discussion
QuickerSite Multiple Vulnerabilities
QuickerSite is prone to multiple vulnerabilities, including an SQL-injection issue, an authentication-bypass issue, multiple cross-site scripting issues, and a file-upload issue.
Successful exploits may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- gain unauthorized access to the affected application
- upload arbitrary files and execute arbitrary server-side script code
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
A successful attack will compromise the application and may help in further attacks.
The issues affect QuickerSite 1.8.5; other versions may also be vulnerable.
QuickerSite is prone to multiple vulnerabilities, including an SQL-injection issue, an authentication-bypass issue, multiple cross-site scripting issues, and a file-upload issue.
Successful exploits may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- gain unauthorized access to the affected application
- upload arbitrary files and execute arbitrary server-side script code
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
A successful attack will compromise the application and may help in further attacks.
The issues affect QuickerSite 1.8.5; other versions may also be vulnerable.
Exploit / POC
QuickerSite Multiple Vulnerabilities
An attacker can exploit these issues through a browser.
An attacker can exploit these issues through a browser.
Solution / Fix
QuickerSite Multiple Vulnerabilities
Solution:
The vendor has released a patch. Please contact the vendor for details.
Solution:
The vendor has released a patch. Please contact the vendor for details.
References
QuickerSite Multiple Vulnerabilities
References:
References:
- QuickerSite Homepage (QuickerSite)
- QuickerSite Multiple Vulnerabilities (AmnPardaz Security Research Team)
- QuickerSite Multiple Vulnerabilities ([email protected])