Interspire Knowledge Manager 5.1.3 and Prior Multiple Remote Vulnerabilities
BID:38090
Info
Interspire Knowledge Manager 5.1.3 and Prior Multiple Remote Vulnerabilities
| Bugtraq ID: | 38090 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2010 12:00AM |
| Updated: | Feb 04 2010 12:00AM |
| Credit: | Cory Marsh |
| Vulnerable: |
Interspire Knowledge Manager 5.1.3 Interspire Knowledge Manager 5.1.2 |
| Not Vulnerable: | |
Discussion
Interspire Knowledge Manager 5.1.3 and Prior Multiple Remote Vulnerabilities
Interspire Knowledge Manager is prone to multiple SQL-injection vulnerabilities, a cross-site scripting vulnerability, and an information-disclosure vulnerability.
Exploiting these issues could allow an attacker to obtain sensitive information, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Interspire Knowledge Manager 5.1.3 and prior versions are vulnerable.
Interspire Knowledge Manager is prone to multiple SQL-injection vulnerabilities, a cross-site scripting vulnerability, and an information-disclosure vulnerability.
Exploiting these issues could allow an attacker to obtain sensitive information, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Interspire Knowledge Manager 5.1.3 and prior versions are vulnerable.
Exploit / POC
Interspire Knowledge Manager 5.1.3 and Prior Multiple Remote Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/admin/de/colormenu.php?sp=f";[xss];a="
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URI is available:
http://www.example.com/admin/de/colormenu.php?sp=f";[xss];a="
Solution / Fix
Interspire Knowledge Manager 5.1.3 and Prior Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Interspire Knowledge Manager 5.1.3 and Prior Multiple Remote Vulnerabilities
References:
References:
- Interspire Homepage (Interspire)