NPDS Versions Prior to 08.06 Multiple Input Validation Vulnerabilities
BID:33051
Info
NPDS Versions Prior to 08.06 Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 33051 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2008 12:00AM |
| Updated: | Jan 02 2009 05:51PM |
| Credit: | Jean-François Leclerc |
| Vulnerable: |
NPDS NPDS 0 |
| Not Vulnerable: |
NPDS NPDS 08.06 |
Discussion
NPDS Versions Prior to 08.06 Multiple Input Validation Vulnerabilities
NPDS is prone to multiple input-validation vulnerabilities:
- Multiple local file-include vulnerabilities
- An HTML-injection vulnerability
- Multiple SQL-injection vulnerabilities
- Multiple cross-site scripting vulnerabilities
Exploiting these issues can allow an attacker to steal cookie-based authentication credentials, view and execute arbitrary local files within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Versions prior to NPDS 08.06 are vulnerable.
NPDS is prone to multiple input-validation vulnerabilities:
- Multiple local file-include vulnerabilities
- An HTML-injection vulnerability
- Multiple SQL-injection vulnerabilities
- Multiple cross-site scripting vulnerabilities
Exploiting these issues can allow an attacker to steal cookie-based authentication credentials, view and execute arbitrary local files within the context of the webserver, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Versions prior to NPDS 08.06 are vulnerable.
Exploit / POC
NPDS Versions Prior to 08.06 Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into visiting a malicious URI.
The following example URIs and exploits are available:
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into visiting a malicious URI.
The following example URIs and exploits are available:
Solution / Fix
NPDS Versions Prior to 08.06 Multiple Input Validation Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Solution:
The vendor released an update to address these issues. Please see the references for more information.
References
NPDS Versions Prior to 08.06 Multiple Input Validation Vulnerabilities
References:
References:
- NPDS Homepage (NPDS)