NoName Script Multiple Remote Vulnerabilities
BID:30816
Info
NoName Script Multiple Remote Vulnerabilities
| Bugtraq ID: | 30816 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2008 12:00AM |
| Updated: | Aug 28 2008 10:44PM |
| Credit: | SirGod |
| Vulnerable: |
NoName Script NoName Script 1.1 BETA |
| Not Vulnerable: | |
Discussion
NoName Script Multiple Remote Vulnerabilities
NoName Script is prone to multiple vulnerabilities including a directory-traversal issue, an SQL-injection issue, and two cross-site request-forgery issues.
Attackers can exploit these issues to:
- view arbitrary local files within the context of the webserver
- edit other users' profile information
- log out an admin user
- compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect NoName Script 1.1 BETA and prior versions.
NoName Script is prone to multiple vulnerabilities including a directory-traversal issue, an SQL-injection issue, and two cross-site request-forgery issues.
Attackers can exploit these issues to:
- view arbitrary local files within the context of the webserver
- edit other users' profile information
- log out an admin user
- compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect NoName Script 1.1 BETA and prior versions.
Exploit / POC
NoName Script Multiple Remote Vulnerabilities
An attacker can exploit these issues via a browser. To exploit some of these issues, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker can exploit these issues via a browser. To exploit some of these issues, the attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
NoName Script Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NoName Script Multiple Remote Vulnerabilities
References:
References: