Atarone Version 1.2.0 Multiple Input Validation Vulnerabilities
BID:31610
Info
Atarone Version 1.2.0 Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 31610 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4489 CVE-2008-4487 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Anonymous |
| Vulnerable: |
Atarone Atarone 1.2 |
| Not Vulnerable: |
Atarone Atarone 1.3 |
Discussion
Atarone Version 1.2.0 Multiple Input Validation Vulnerabilities
Atarone is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include multiple cross-site scripting issues, multiple SQL-injection issues, and a local file-include issue.
Exploiting these issues can allow an attacker to steal cookie-based authentication credentials, view local files within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Atarone 1.2.0 is vulnerable; other versions may also be affected.
Atarone is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include multiple cross-site scripting issues, multiple SQL-injection issues, and a local file-include issue.
Exploiting these issues can allow an attacker to steal cookie-based authentication credentials, view local files within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Atarone 1.2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Atarone Version 1.2.0 Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into visiting a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into visiting a malicious URI.
Solution / Fix
Atarone Version 1.2.0 Multiple Input Validation Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Atarone Atarone 1.2
Solution:
Updates are available; please see the references for more information.
Atarone Atarone 1.2
-
Atarone atarone13.tar.gz
http://downloads.sourceforge.net/atarone/atarone13.tar.gz?modtime=1228 583147&big_mirror=0
References
Atarone Version 1.2.0 Multiple Input Validation Vulnerabilities
References:
References:
- Atarone SourceForge Page (Atarone)
- Release Name: 1.3 (Atarone)