Nullam Blog Multiple Input Validation Vulnerabilities
BID:42965
Info
Nullam Blog Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 42965 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2009 12:00AM |
| Updated: | Sep 10 2009 12:00AM |
| Credit: | Salvatore Fresta aka drosophila |
| Vulnerable: |
Dylan McGannon Nullam Blog 0.1.2 |
| Not Vulnerable: | |
Discussion
Nullam Blog Multiple Input Validation Vulnerabilities
Nullam Blog is prone to multiple input-validation vulnerabilities, including a local file-include vulnerability, a local file-disclosure vulnerability, multiple SQL-injection vulnerabilities, and a cross-site scripting vulnerability.
An attacker can exploit these vulnerabilities to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, obtain potentially sensitive information, or execute arbitrary local scripts in the context of the webserver process; other attacks are also possible.
Nullam Blog 0.1.2 is vulnerable; other versions may also be affected.
Nullam Blog is prone to multiple input-validation vulnerabilities, including a local file-include vulnerability, a local file-disclosure vulnerability, multiple SQL-injection vulnerabilities, and a cross-site scripting vulnerability.
An attacker can exploit these vulnerabilities to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, obtain potentially sensitive information, or execute arbitrary local scripts in the context of the webserver process; other attacks are also possible.
Nullam Blog 0.1.2 is vulnerable; other versions may also be affected.
Exploit / POC
Nullam Blog Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
The following example URIs are available:
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
The following example URIs are available:
Solution / Fix
Nullam Blog Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Nullam Blog Multiple Input Validation Vulnerabilities
References:
References:
- Nullam Blog Project Page (SourceForge)
- Nullam Blog Multiple Remote Vulnerabilities (Salvatore Fresta aka Drosophila)