RavenNuke Multiple Input Validation Vulnerabilities
BID:33787
Info
RavenNuke Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 33787 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0679 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2009 12:00AM |
| Updated: | Mar 09 2009 02:56PM |
| Credit: | Janek Vind "waraxe" |
| Vulnerable: |
Raven Web Services Inc. RavenNuke 2.30 |
| Not Vulnerable: |
Raven Web Services Inc. RavenNuke 2.30.1 |
Discussion
RavenNuke Multiple Input Validation Vulnerabilities
RavenNuke is prone to the following input-validation vulnerabilities:
- Multiple remote code-execution vulnerabilities
- An SQL-injection vulnerability
- Multiple cross-site scripting vulnerabilities
An attacker can exploit these issues to execute arbitrary code within the context of the webserver, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or obtain sensitive information. Other attacks are also possible.
Versions prior to RavenNuke 2.30.01 are vulnerable.
RavenNuke is prone to the following input-validation vulnerabilities:
- Multiple remote code-execution vulnerabilities
- An SQL-injection vulnerability
- Multiple cross-site scripting vulnerabilities
An attacker can exploit these issues to execute arbitrary code within the context of the webserver, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or obtain sensitive information. Other attacks are also possible.
Versions prior to RavenNuke 2.30.01 are vulnerable.
Exploit / POC
RavenNuke Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser. Please see the references for examples.
Attackers can exploit these issues via a browser. Please see the references for examples.
Solution / Fix
RavenNuke Multiple Input Validation Vulnerabilities
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
RavenNuke Multiple Input Validation Vulnerabilities
References:
References:
- Vendor Homepage (Raven Web Services)
- [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0 ([email protected])
- RavenNuke 2.30.01 (Raven Web Services)