TGS Content Management Multiple Input Validation Vulnerabilities
BID:36401
Info
TGS Content Management Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 36401 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2929 CVE-2009-2928 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2009 12:00AM |
| Updated: | Sep 15 2009 11:21PM |
| Credit: | []ViZiOn |
| Vulnerable: |
TGS Content Management TGS Content Management 0 |
| Not Vulnerable: | |
Discussion
TGS Content Management Multiple Input Validation Vulnerabilities
TGS Content Management is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. These issues include:
1. A cross-site scripting issue.
2. Multiple SQL-injection issues.
3. An information-disclosure issue.
Exploiting these issues could allow an attacker to obtain sensitive information, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TGS Content Management is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. These issues include:
1. A cross-site scripting issue.
2. Multiple SQL-injection issues.
3. An information-disclosure issue.
Exploiting these issues could allow an attacker to obtain sensitive information, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
TGS Content Management Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/cms/index.php?tgs_language_id=[SQL Injection]
http://www.example.com/cms/index.php?tpl_dir=[SQL Injection]
http://www.example.com/cms/index.php?referer=[SQL Injection]
http://www.example.com/cms/index.php?user-agent=[SQL Injection]
http://www.example.com/cms/index.php?site=[SQL Injection]
http://www.example.com/cms/index.php?option=[SQL Injection]
http://www.example.com/cms/index.php?db_optimization=[SQL Injection]
http://www.example.com/cms/index.php?owner=[SQL Injection]
http://www.example.com/cms/index.php?admin_email=[SQL Injection]
http://www.example.com/cms/index.php?default_language=[SQL Injection]
http://www.example.com/cms/index.php?db_host=[SQL Injection]
http://www.example.com/cms/frontpage_ception.php?cmd=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?s_dir=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?minutes=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?s_mask=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?test3_mp=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?test15_file1=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?submit=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?brute_method=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?ftp_server_port=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?userfile14=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?subj=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?mysql_l=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?action=[Blind SQL
http://www.example.com/cms/frontpage_ception.php?userfile1=[Blind SQL]
http://www.example.com/cms/index.php (site=admin)
http://www.example.com/cms/admin.php
http://www.example.com/cms/index.php (site=admin)
http://www.example.com/cms/login.php?previous_page=[XSS]
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/cms/index.php?tgs_language_id=[SQL Injection]
http://www.example.com/cms/index.php?tpl_dir=[SQL Injection]
http://www.example.com/cms/index.php?referer=[SQL Injection]
http://www.example.com/cms/index.php?user-agent=[SQL Injection]
http://www.example.com/cms/index.php?site=[SQL Injection]
http://www.example.com/cms/index.php?option=[SQL Injection]
http://www.example.com/cms/index.php?db_optimization=[SQL Injection]
http://www.example.com/cms/index.php?owner=[SQL Injection]
http://www.example.com/cms/index.php?admin_email=[SQL Injection]
http://www.example.com/cms/index.php?default_language=[SQL Injection]
http://www.example.com/cms/index.php?db_host=[SQL Injection]
http://www.example.com/cms/frontpage_ception.php?cmd=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?s_dir=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?minutes=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?s_mask=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?test3_mp=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?test15_file1=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?submit=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?brute_method=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?ftp_server_port=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?userfile14=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?subj=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?mysql_l=[Blind SQL]
http://www.example.com/cms/frontpage_ception.php?action=[Blind SQL
http://www.example.com/cms/frontpage_ception.php?userfile1=[Blind SQL]
http://www.example.com/cms/index.php (site=admin)
http://www.example.com/cms/admin.php
http://www.example.com/cms/index.php (site=admin)
http://www.example.com/cms/login.php?previous_page=[XSS]
Solution / Fix
TGS Content Management Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TGS Content Management Multiple Input Validation Vulnerabilities
References:
References:
- TGS Content Management Homepage (TGS Content Management)