PHD Help Desk Multiple Cross Site Scripting Vulnerabilities
BID:37029
Info
PHD Help Desk Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 37029 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2009 12:00AM |
| Updated: | Nov 16 2009 07:46PM |
| Credit: | Amol Naik |
| Vulnerable: |
PHD Help Desk PHD Help Desk 1.43 |
| Not Vulnerable: | |
Discussion
PHD Help Desk Multiple Cross Site Scripting Vulnerabilities
PHD Help Desk is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials; other attacks are also possible.
PHD Help Desk 1.43 is vulnerable; other versions may also be affected.
PHD Help Desk is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials; other attacks are also possible.
PHD Help Desk 1.43 is vulnerable; other versions may also be affected.
Exploit / POC
PHD Help Desk Multiple Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/area.php/[code]
http://www.example.com/area.php?pagina=[code]
http://www.example.com/area.php?sentido=[code]
http://www.example.com/area.php?q_registros=[code]
http://www.example.com/area.php?orden=[code]
http://www.example.com/solic_display.php?pagina=1&q_registros=[code]&orden=seq_solicitud_id
http://www.example.com/area_list.php/[code]
http://www.example.com/area_list.php?pagina=1&q_registros=0[code]&orden=nombre
http://www.example.com/atributo.php/[code]
http://www.example.com/atributo_list.php?pagina=1[code]&q_registros=15&orden=activo&sentido
http://www.example.com/atributo_list.php?pagina=1&q_registros=15[code]&orden=activo&sentido
http://www.example.com/atributo_list.php?pagina=1&q_registros=15&orden=activo[code]&sentido
http://www.example.com/atributo_list.php?pagina=1&q_registros=15&orden=activo&sentido[code]
http://www.example.com/caso_insert.php/[code]
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example URIs are available:
http://www.example.com/area.php/[code]
http://www.example.com/area.php?pagina=[code]
http://www.example.com/area.php?sentido=[code]
http://www.example.com/area.php?q_registros=[code]
http://www.example.com/area.php?orden=[code]
http://www.example.com/solic_display.php?pagina=1&q_registros=[code]&orden=seq_solicitud_id
http://www.example.com/area_list.php/[code]
http://www.example.com/area_list.php?pagina=1&q_registros=0[code]&orden=nombre
http://www.example.com/atributo.php/[code]
http://www.example.com/atributo_list.php?pagina=1[code]&q_registros=15&orden=activo&sentido
http://www.example.com/atributo_list.php?pagina=1&q_registros=15[code]&orden=activo&sentido
http://www.example.com/atributo_list.php?pagina=1&q_registros=15&orden=activo[code]&sentido
http://www.example.com/atributo_list.php?pagina=1&q_registros=15&orden=activo&sentido[code]
http://www.example.com/caso_insert.php/[code]
Solution / Fix
PHD Help Desk Multiple Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHD Help Desk Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Vendor Homepage (PHD Help Desk)