ADbNewsSender SQL Injection and Cross Site Scripting Vulnerabilities
BID:32903
Info
ADbNewsSender SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 32903 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2008 12:00AM |
| Updated: | Dec 29 2008 07:42PM |
| Credit: | ADbNewsSender |
| Vulnerable: |
ADbNewsSender ADbNewsSender 1.5.1 |
| Not Vulnerable: |
ADbNewsSender ADbNewsSender 1.5.2 |
Discussion
ADbNewsSender SQL Injection and Cross Site Scripting Vulnerabilities
ADbNewsSender is prone to multiple SQL-injection vulnerabilities and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to ADbNewsSender 1.5.2 are affected.
ADbNewsSender is prone to multiple SQL-injection vulnerabilities and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to ADbNewsSender 1.5.2 are affected.
Exploit / POC
ADbNewsSender SQL Injection and Cross Site Scripting Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
ADbNewsSender SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an update to address the issues. Please see the references for more information.
ADbNewsSender ADbNewsSender 1.5.1
Solution:
The vendor has released an update to address the issues. Please see the references for more information.
ADbNewsSender ADbNewsSender 1.5.1
-
ADbNewsSender ADbNewsSender_1.5.2.zip
http://downloads.sourceforge.net/adbnewssender/ADbNewsSender_1.5.2.zip ?modtime=1229545668&big_mirror=0
References
ADbNewsSender SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- ADbNewsSender Changelog 1.5.2 (ADbNewsSender)
- ADbNewsSender Homepage (ADbNewsSender)