IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities
BID:30414
Info
IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 30414 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2008 12:00AM |
| Updated: | Jul 29 2008 06:27PM |
| Credit: | Robert S. aka bloo. |
| Vulnerable: |
IDevSpot BizDirectory 2.06 IDevSpot BizDirectory 2.05 IDevSpot BizDirectory 2.04 IDevSpot BizDirectory 2.03 IDevSpot BizDirectory 2.02 IDevSpot BizDirectory 2.01 IDevSpot BizDirectory 2.0 |
| Not Vulnerable: |
IDevSpot BizDirectory 2.09 IDevSpot BizDirectory 2.08 IDevSpot BizDirectory 2.07 |
Discussion
IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities
IDevSpot BizDirectory is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include SQL-injection and cross-site scripting vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to IDevSpot BizDirectory 2.07 are vulnerable.
IDevSpot BizDirectory is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include SQL-injection and cross-site scripting vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to IDevSpot BizDirectory 2.07 are vulnerable.
Exploit / POC
IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
The vendor released BizDirectory 2.07 to address these issues. Please see the references for more information.
Solution:
The vendor released BizDirectory 2.07 to address these issues. Please see the references for more information.
References
IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- BizDirectory Homepage (IDevShop)
- IDevSpot BizDirectory Patch Notes 2.07 (IDevShop)