TSEP Multiple Remote Vulnerabilities
BID:35539
Info
TSEP Multiple Remote Vulnerabilities
| Bugtraq ID: | 35539 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2009 12:00AM |
| Updated: | Jun 30 2009 10:09PM |
| Credit: | eLwaux |
| Vulnerable: |
TSEP TSEP 0.942.2 TSEP TSEP 0.942 |
| Not Vulnerable: | |
Discussion
TSEP Multiple Remote Vulnerabilities
TSEP (The Search Engine Project) is prone to multiple vulnerabilities:
- Multiple information-disclosure vulnerabilities
- Multiple SQL-injection vulnerabilities
- Multiple cross-site scripting vulnerabilities
- A local file-include vulnerability
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, obtain sensitive information, execute arbitrary local scripts, access or modify data, or exploit latent vulnerabilities in the underlying database.
TSEP (The Search Engine Project) is prone to multiple vulnerabilities:
- Multiple information-disclosure vulnerabilities
- Multiple SQL-injection vulnerabilities
- Multiple cross-site scripting vulnerabilities
- A local file-include vulnerability
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, obtain sensitive information, execute arbitrary local scripts, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
TSEP Multiple Remote Vulnerabilities
Attackers can use a browser to exploit these issues. For a cross-site scripting issue, an unsuspecting user must be enticed into following a malicious link.
The following example URIs and data are available:
Attackers can use a browser to exploit these issues. For a cross-site scripting issue, an unsuspecting user must be enticed into following a malicious link.
The following example URIs and data are available:
Solution / Fix
TSEP Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].