Simplog Multiple Remote Vulnerabilities
BID:37063
Info
Simplog Multiple Remote Vulnerabilities
| Bugtraq ID: | 37063 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2009 12:00AM |
| Updated: | Nov 19 2009 05:06PM |
| Credit: | Amol Naik |
| Vulnerable: |
Simplog Simplog 0.9.3 .2 |
| Not Vulnerable: | |
Discussion
Simplog Multiple Remote Vulnerabilities
Simplog is prone to multiple remote issues, including:
- Multiple HTML-injection vulnerabilities
- A cross-site request-forgery vulnerability
- A security-bypass vulnerability
An attacker could exploit these issues to steal cookie-based authentication credentials, perform unauthorized actions, or bypass certain security restrictions. Other attacks are also possible.
These issues affect Simplog 0.9.3.2; other versions may also be affected.
Simplog is prone to multiple remote issues, including:
- Multiple HTML-injection vulnerabilities
- A cross-site request-forgery vulnerability
- A security-bypass vulnerability
An attacker could exploit these issues to steal cookie-based authentication credentials, perform unauthorized actions, or bypass certain security restrictions. Other attacks are also possible.
These issues affect Simplog 0.9.3.2; other versions may also be affected.
Exploit / POC
Simplog Multiple Remote Vulnerabilities
An attacker can use a browser to exploit these issues. For a cross-site request-forgery attack, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/simplog/user.php?pass1=AMol_NAik&pass2=AMol_NAik&blogid=1&act=change
http://www.example.com/simplog/comments.php?op=edit&cid=
http://www.example.com/simplog/comments.php?op=del&cid=
The following input examples are available:
Name: alert("AMol_NAik")
Email:">alert("AMol_NAik")
An attacker can use a browser to exploit these issues. For a cross-site request-forgery attack, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/simplog/user.php?pass1=AMol_NAik&pass2=AMol_NAik&blogid=1&act=change
http://www.example.com/simplog/comments.php?op=edit&cid=
http://www.example.com/simplog/comments.php?op=del&cid=
The following input examples are available:
Name: alert("AMol_NAik")
Email:">alert("AMol_NAik")
Solution / Fix
Simplog Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Simplog Multiple Remote Vulnerabilities
References:
References:
- Mutliple Vulnerabilities in Simplog v0.9.3.2 (Amol Naik)
- Simplog Web Site (Simplog)