Opial Multiple Vulnerabilities
BID:35641
Info
Opial Multiple Vulnerabilities
| Bugtraq ID: | 35641 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3753 CVE-2009-3752 CVE-2009-3751 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2009 12:00AM |
| Updated: | Oct 27 2009 09:18PM |
| Credit: | LMaster |
| Vulnerable: |
Opial Opial 1.0 |
| Not Vulnerable: | |
Discussion
Opial Multiple Vulnerabilities
Opial is prone to multiple vulnerabilities, including an SQL-injection issue, a cross-site scripting issue, and a file-upload issue.
Successful exploits may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- gain unauthorized access to the affected application
- upload arbitrary files and execute arbitrary server-side script code
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
A successful attack will compromise the application and may help in further attacks.
The issues affect Opial 10; other versions may also be vulnerable.
Opial is prone to multiple vulnerabilities, including an SQL-injection issue, a cross-site scripting issue, and a file-upload issue.
Successful exploits may allow attackers to:
- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- gain unauthorized access to the affected application
- upload arbitrary files and execute arbitrary server-side script code
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
A successful attack will compromise the application and may help in further attacks.
The issues affect Opial 10; other versions may also be vulnerable.
Exploit / POC
Opial Multiple Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/home.php?genres_parent=-1%20union/**/select/**/1,concat(user(),%27%20%27,version()),3,4,5,6--
http://www.example.com/home.php?genres_parent=%22%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E
An attacker can exploit these issues through a browser.
The following example URIs are available:
http://www.example.com/home.php?genres_parent=-1%20union/**/select/**/1,concat(user(),%27%20%27,version()),3,4,5,6--
http://www.example.com/home.php?genres_parent=%22%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E
Solution / Fix
Opial Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].