Artica Multiple Security Vulnerabilities
BID:43613
Info
Artica Multiple Security Vulnerabilities
| Bugtraq ID: | 43613 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2010 12:00AM |
| Updated: | Sep 30 2010 12:00AM |
| Credit: | Julien Cayssol |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Artica Multiple Security Vulnerabilities
Artica is prone to multiple security vulnerabilities including directory-traversal vulnerabilities, security-bypass vulnerabilities, an SQL-injection issue, and an unspecified cross-site scripting issue.
Successfully exploiting the directory-traversal issues allows attackers to view arbitrary local files and directories within the context of the webserver.
Attackers can exploit the SQL-injection issue to carry out unauthorized actions on the underlying database.
Successfully exploiting the security-bypass issues allows remote attackers to bypass certain security restrictions and perform unauthorized actions.
Attackers can exploit the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials or launch other attacks.
Artica 1.4.090119 is vulnerable; other versions may also be affected.
Artica is prone to multiple security vulnerabilities including directory-traversal vulnerabilities, security-bypass vulnerabilities, an SQL-injection issue, and an unspecified cross-site scripting issue.
Successfully exploiting the directory-traversal issues allows attackers to view arbitrary local files and directories within the context of the webserver.
Attackers can exploit the SQL-injection issue to carry out unauthorized actions on the underlying database.
Successfully exploiting the security-bypass issues allows remote attackers to bypass certain security restrictions and perform unauthorized actions.
Attackers can exploit the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials or launch other attacks.
Artica 1.4.090119 is vulnerable; other versions may also be affected.
Exploit / POC
Artica Multiple Security Vulnerabilities
Attackers can exploit these issues via a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can exploit these issues via a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
Artica Multiple Security Vulnerabilities
Solution:
The vendor released a patch. Please see the references for more information.
Solution:
The vendor released a patch. Please see the references for more information.
References
Artica Multiple Security Vulnerabilities
References:
References:
- Artica Nightly Builds Homepage (Artica Nightly Builds)
- Artica Open Source Project Homepage (Artica Open Source Project)