e107 Cross Site Scripting and SQL Injection Vulnerabilities
BID:37087
Info
e107 Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 37087 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4083 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2009 12:00AM |
| Updated: | Apr 13 2015 09:05PM |
| Credit: | Do Hoang Bach, Bkis |
| Vulnerable: |
e107 e107 0.7.16 |
| Not Vulnerable: | |
Discussion
e107 Cross Site Scripting and SQL Injection Vulnerabilities
e107 is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
e107 0.7.16 and prior versions are affected.
e107 is prone to an SQL-injection vulnerability and multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
e107 0.7.16 and prior versions are affected.
Exploit / POC
e107 Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
e107 Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
e107 Cross Site Scripting and SQL Injection Vulnerabilities
References:
References: