Hulihan Applications BXR SQL Injection and HTML Injection Vulnerabilities
BID:42247
Info
Hulihan Applications BXR SQL Injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 42247 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-4963 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2010 12:00AM |
| Updated: | Mar 19 2015 09:15AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
Hulihan Applications BXR 0.6.8 |
| Not Vulnerable: | |
Discussion
Hulihan Applications BXR SQL Injection and HTML Injection Vulnerabilities
Hulihan Applications BXR is prone to an SQL-injection vulnerability and multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.
Hulihan Applications BXR 0.6.8 is vulnerable; other versions may also be affected.
Hulihan Applications BXR is prone to an SQL-injection vulnerability and multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.
Hulihan Applications BXR 0.6.8 is vulnerable; other versions may also be affected.
Exploit / POC
Hulihan Applications BXR SQL Injection and HTML Injection Vulnerabilities
An attacker can exploit these issues through a browser.
The following examples are available:
An attacker can exploit these issues through a browser.
The following examples are available:
Solution / Fix
Hulihan Applications BXR SQL Injection and HTML Injection Vulnerabilities
Solution:
Reports indicate that updates are available; Symantec has not verified this. Please see the references for more information.
Solution:
Reports indicate that updates are available; Symantec has not verified this. Please see the references for more information.
References
Hulihan Applications BXR SQL Injection and HTML Injection Vulnerabilities
References:
References:
- BXR - 0.6.9 - Hulihan Applications Software Development System (Hulihan Applications)
- BXR Homepage (Hulihan Applications)
- SQL injection vulnerability in BXR ([email protected])
- XSS vulnerability in BXR ([email protected])
- XSS vulnerability in BXR ([email protected])
- XSS vulnerability in BXR search ([email protected])