OpenX 2.6.3 Multiple Input Validation Vulnerabilities
BID:33468
Info
OpenX 2.6.3 Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 33468 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0291 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2009 12:00AM |
| Updated: | Apr 02 2009 02:06PM |
| Credit: | Sarid Harper of Secunia |
| Vulnerable: |
OpenX OpenX 2.6.4 OpenX OpenX 2.6.2 OpenX OpenX 2.6.1 OpenX OpenX 2.4.10 OpenX OpenX 2.4.9 OpenX OpenX 2.4.8 OpenX OpenX 2.7.29-beta OpenX Openads 2.0.11 |
| Not Vulnerable: |
OpenX OpenX 2.6.5 OpenX OpenX 2.4.11 OpenX OpenX 2.8 |
Discussion
OpenX 2.6.3 Multiple Input Validation Vulnerabilities
OpenX is prone to multiple input-validation vulnerabilities:
- Multiple cross-site scripting vulnerabilities
- Multiple HTML-injection vulnerabilities
- Multiple SQL-Injection vulnerabilities
Attackers can exploit these issues to steal cookie-based authentication credentials from legitimate users of the site, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to OpenX 2.6.4 and 2.4.10 are vulnerable.
OpenX is prone to multiple input-validation vulnerabilities:
- Multiple cross-site scripting vulnerabilities
- Multiple HTML-injection vulnerabilities
- Multiple SQL-Injection vulnerabilities
Attackers can exploit these issues to steal cookie-based authentication credentials from legitimate users of the site, modify the way the site is rendered, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to OpenX 2.6.4 and 2.4.10 are vulnerable.
Exploit / POC
OpenX 2.6.3 Multiple Input Validation Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
OpenX 2.6.3 Multiple Input Validation Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
NOTE: Earlier updates did not properly correct all the issues reported. The vendor has released additional updates to address the issues.
Solution:
Vendor updates are available. Please see the references for more information.
NOTE: Earlier updates did not properly correct all the issues reported. The vendor has released additional updates to address the issues.
References
OpenX 2.6.3 Multiple Input Validation Vulnerabilities
References:
References:
- OpenX Homepage (OpenX)
- [OPENX-SA-2009-001] OpenX 2.4.10 and 2.6.4 fix multiple vulnerabilities (Matteo Beccati
) - Re: Secunia Research: OpenX Multiple Vulnerabilities ([email protected])
- Secunia Research: OpenX Multiple Vulnerabilities (Secunia Research
) - Secunia Research: OpenX Multiple Vulnerabilities (Secunia)