Limny 2.01 Multiple Remote Vulnerabilities
BID:38859
Info
Limny 2.01 Multiple Remote Vulnerabilities
| Bugtraq ID: | 38859 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2010 12:00AM |
| Updated: | Mar 19 2010 12:00AM |
| Credit: | Moist von Lipwig |
| Vulnerable: |
Limny Limny 2.01 |
| Not Vulnerable: | |
Discussion
Limny 2.01 Multiple Remote Vulnerabilities
Limny is prone to multiple remote vulnerabilities, including:
- Multiple HTML-injection vulnerabilities
- Multiple SQL-injection vulnerabilities
- Multiple security-bypass vulnerabilities
- Multiple cross-site scripting vulnerabilities.
The attacker may exploit these issues to compromise the application, execute arbitrary code, steal cookie-based authentication credentials, gain unauthorized access to the application, modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are also possible.
Limny 2.01 is vulnerable; other versions may also be affected.
Limny is prone to multiple remote vulnerabilities, including:
- Multiple HTML-injection vulnerabilities
- Multiple SQL-injection vulnerabilities
- Multiple security-bypass vulnerabilities
- Multiple cross-site scripting vulnerabilities.
The attacker may exploit these issues to compromise the application, execute arbitrary code, steal cookie-based authentication credentials, gain unauthorized access to the application, modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are also possible.
Limny 2.01 is vulnerable; other versions may also be affected.
Exploit / POC
Limny 2.01 Multiple Remote Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability an attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability an attacker must entice an unsuspecting victim to follow a malicious URI.