Lightweight news portal Multiple Input Validation and Authentication Bypass Vulnerabilities
BID:29848
Info
Lightweight news portal Multiple Input Validation and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 29848 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7172 CVE-2008-7171 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | sToRm |
| Vulnerable: |
Yanick Bourbeau Lightweight news portal 1.0b |
| Not Vulnerable: | |
Discussion
Lightweight news portal Multiple Input Validation and Authentication Bypass Vulnerabilities
Lightweight news portal is prone to multiple vulnerabilities, including two cross-site scripting issues, an HTML-injection issue, an authentication-bypass issue, and an arbitrary-file-upload issue.
Attackers can leverage these issues to execute arbitrary HTML or script code in the context of the affected site or access certain administrative functions. This can allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, launch denial-of-service attacks, and compromise the application; other attacks are also possible.
Lightweight news portal 1.0b is vulnerable; other versions may also be affected.
Lightweight news portal is prone to multiple vulnerabilities, including two cross-site scripting issues, an HTML-injection issue, an authentication-bypass issue, and an arbitrary-file-upload issue.
Attackers can leverage these issues to execute arbitrary HTML or script code in the context of the affected site or access certain administrative functions. This can allow the attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, launch denial-of-service attacks, and compromise the application; other attacks are also possible.
Lightweight news portal 1.0b is vulnerable; other versions may also be affected.
Exploit / POC
Lightweight news portal Multiple Input Validation and Authentication Bypass Vulnerabilities
Attackers can exploit these issues using a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a specially crafted URI.
The following proof-of-concept URIs are available:
Attackers can exploit these issues using a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a specially crafted URI.
The following proof-of-concept URIs are available:
Solution / Fix
Lightweight news portal Multiple Input Validation and Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Lightweight news portal Multiple Input Validation and Authentication Bypass Vulnerabilities
References:
References:
- Lightweight news portal Download Page (Yanick Bourbeau)