AssetMan 'search_inv.php' Multiple Vulnerabilities
BID:31248
Info
AssetMan 'search_inv.php' Multiple Vulnerabilities
| Bugtraq ID: | 31248 |
| Class: | Unknown |
| CVE: |
CVE-2008-4161 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Neo Anderson & Jackh4xor |
| Vulnerable: |
Assetman Assetman 2.5b |
| Not Vulnerable: | |
Discussion
AssetMan 'search_inv.php' Multiple Vulnerabilities
AssetMan is prone to multiple vulnerabilities, including session-fixation, cross-site scripting, and SQL-injection issues.
Attackers can exploit these issues to hijack a user's session, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect AssetMan 2.5b; other versions may also be affected.
AssetMan is prone to multiple vulnerabilities, including session-fixation, cross-site scripting, and SQL-injection issues.
Attackers can exploit these issues to hijack a user's session, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect AssetMan 2.5b; other versions may also be affected.
Exploit / POC
AssetMan 'search_inv.php' Multiple Vulnerabilities
An attacker can exploit these issues via a browser. To exploit cross-site scripting and session-fixation issues, the attacker entices an unsuspecting victim to following a malicious URI.
The following example URI is available:
http://www.example.com/assetman/search_inv.php?action=search_all&order_by=%3Cmeta+http-equiv='Set-cookie'+content='=value'%3E&order=DESC+limit+1,1--
An attacker can exploit these issues via a browser. To exploit cross-site scripting and session-fixation issues, the attacker entices an unsuspecting victim to following a malicious URI.
The following example URI is available:
http://www.example.com/assetman/search_inv.php?action=search_all&order_by=%3Cmeta+http-equiv='Set-cookie'+content='=value'%3E&order=DESC+limit+1,1--
Solution / Fix
AssetMan 'search_inv.php' Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].