Dating Agent PRO SQL Injection and HTML Injection Vulnerabilities
BID:37614
Info
Dating Agent PRO SQL Injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 37614 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2010 12:00AM |
| Updated: | Jan 05 2010 12:00AM |
| Credit: | Nobbs |
| Vulnerable: |
Dating Agent Dating Agent PRO 4.9.1 Dating Agent Dating Agent PRO 4.7.1 |
| Not Vulnerable: | |
Discussion
Dating Agent PRO SQL Injection and HTML Injection Vulnerabilities
Dating Agent PRO is prone to an HTML-injection vulnerability and multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage the HTML-injection issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.
The attacker can exploit the SQL-injection issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Note that some of these issues may require valid user credentials, which may be an automated or trivial task.
Dating Agent PRO 4.9.1 is vulnerable; other versions may also be affected.
Dating Agent PRO is prone to an HTML-injection vulnerability and multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage the HTML-injection issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.
The attacker can exploit the SQL-injection issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Note that some of these issues may require valid user credentials, which may be an automated or trivial task.
Dating Agent PRO 4.9.1 is vulnerable; other versions may also be affected.
Exploit / POC
Dating Agent PRO SQL Injection and HTML Injection Vulnerabilities
An attacker can exploit these issues via a browser.
An attacker can exploit these issues via a browser.
Solution / Fix
Dating Agent PRO SQL Injection and HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Dating Agent PRO SQL Injection and HTML Injection Vulnerabilities
References:
References:
- Dating Agent Homepage (Dating Agent)