Open-Audit Multiple Vulnerabilities
BID:40315
Info
Open-Audit Multiple Vulnerabilities
| Bugtraq ID: | 40315 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2010 12:00AM |
| Updated: | May 20 2010 12:00AM |
| Credit: | Sébastien Duquette |
| Vulnerable: |
Open-Audit Open-Audit 20091223-RC Open-Audit Open-Audit 20081013 |
| Not Vulnerable: | |
Discussion
Open-Audit Multiple Vulnerabilities
Open-Audit is prone to multiple vulnerabilities, including a local file-include vulnerability and multiple SQL-injection, cross-site scripting, and authentication-bypass vulnerabilities.
An attacker can exploit these vulnerabilities to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, bypass security restrictions, obtain potentially sensitive information, perform unauthorized actions, or execute arbitrary local scripts in the context of the webserver process; other attacks are also possible.
Open-Audit 20081013 and 20091223-RC are vulnerable; other versions may also be affected.
Open-Audit is prone to multiple vulnerabilities, including a local file-include vulnerability and multiple SQL-injection, cross-site scripting, and authentication-bypass vulnerabilities.
An attacker can exploit these vulnerabilities to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, bypass security restrictions, obtain potentially sensitive information, perform unauthorized actions, or execute arbitrary local scripts in the context of the webserver process; other attacks are also possible.
Open-Audit 20081013 and 20091223-RC are vulnerable; other versions may also be affected.
Exploit / POC
Open-Audit Multiple Vulnerabilities
An attacker can carry out this attack using readily available network utilities.
The following examples are available:
An attacker can carry out this attack using readily available network utilities.
The following examples are available:
Solution / Fix
Open-Audit Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].