Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities
BID:29813
Info
Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 29813 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2969 CVE-2008-2970 CVE-2008-2878 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | AmnPardaz Security Research Team |
| Vulnerable: |
Yektaweb Academic Webtools CMS 1.4.2.8 |
| Not Vulnerable: | |
Discussion
Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities
Academic Web Tools CMS is prone to multiple input-validation vulnerabilities:
- A directory-traversal vulnerability
- Multiple cross-site scripting vulnerabilities
- An HTML-injection vulnerability
- An SQL-injection vulnerability
- Multiple session-fixation vulnerabilities
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, gain unauthorized access to the affected application, access or modify data, execute arbitrary local scripts, retrieve potentially sensitive information, or exploit latent vulnerabilities in the underlying database.
Academic Web Tools CMS 1.4.2.8 is vulnerable; other versions may also be affected.
Academic Web Tools CMS is prone to multiple input-validation vulnerabilities:
- A directory-traversal vulnerability
- Multiple cross-site scripting vulnerabilities
- An HTML-injection vulnerability
- An SQL-injection vulnerability
- Multiple session-fixation vulnerabilities
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, gain unauthorized access to the affected application, access or modify data, execute arbitrary local scripts, retrieve potentially sensitive information, or exploit latent vulnerabilities in the underlying database.
Academic Web Tools CMS 1.4.2.8 is vulnerable; other versions may also be affected.
Exploit / POC
Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs and exploit code are available:
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs and exploit code are available:
Solution / Fix
Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Academic Web Tools CMS 1.4.2.8 Multiple Input Validation Vulnerabilities
References:
References: