Webmatic Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
BID:29748
Info
Webmatic Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 29748 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2924 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Valarsoft WebMatic 2.6.2 Valarsoft WebMatic 2.6.1 Valarsoft WebMatic 2.7 Valarsoft WebMatic 2.6 |
| Not Vulnerable: |
Valarsoft WebMatic 2.8 |
Discussion
Webmatic Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
Webmatic is prone to multiple cross-site scripting and SQL-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Webmatic 2.8 are vulnerable.
Webmatic is prone to multiple cross-site scripting and SQL-injection vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Webmatic 2.8 are vulnerable.
Exploit / POC
Webmatic Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim into following a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice a victim into following a malicious URI.
Solution / Fix
Webmatic Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Valarsoft WebMatic 2.7
Valarsoft WebMatic 2.6
Valarsoft WebMatic 2.6.1
Valarsoft WebMatic 2.6.2
Solution:
The vendor has released updates. Please see the references for more information.
Valarsoft WebMatic 2.7
-
Valarsoft Webmatic 2.8 Download
http://www.valarsoft.com/index.php?dpage=pagine&page=downloads&pagID=1 56&arg_downID=1&sub_downID=1&downID=17
Valarsoft WebMatic 2.6
-
Valarsoft Webmatic 2.8 Download
http://www.valarsoft.com/index.php?dpage=pagine&page=downloads&pagID=1 56&arg_downID=1&sub_downID=1&downID=17
Valarsoft WebMatic 2.6.1
-
Valarsoft Webmatic 2.8 Download
http://www.valarsoft.com/index.php?dpage=pagine&page=downloads&pagID=1 56&arg_downID=1&sub_downID=1&downID=17
Valarsoft WebMatic 2.6.2
-
Valarsoft Webmatic 2.8 Download
http://www.valarsoft.com/index.php?dpage=pagine&page=downloads&pagID=1 56&arg_downID=1&sub_downID=1&downID=17
References
Webmatic Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
References:
References:
- Webmatic 2.8 released (Valarsoft)
- Webmatic Homepage (Valarsoft)