Virtue Online Test Generator Multiple Security Vulnerabilities
BID:43832
Info
Virtue Online Test Generator Multiple Security Vulnerabilities
| Bugtraq ID: | 43832 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2391 CVE-2009-2392 CVE-2009-2393 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2009 12:00AM |
| Updated: | Oct 26 2009 12:00AM |
| Credit: | HxH |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Virtue Online Test Generator Multiple Security Vulnerabilities
Virtue Online Test Generator is prone to multiple security vulnerabilities including an authentication-bypass vulnerability, a cross-site-scripting vulnerability, and an SQL-injection vulnerability.
Exploiting these vulnerabilities could allow an attacker to gain administrative access to the affected application, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Virtue Online Test Generator is prone to multiple security vulnerabilities including an authentication-bypass vulnerability, a cross-site-scripting vulnerability, and an SQL-injection vulnerability.
Exploiting these vulnerabilities could allow an attacker to gain administrative access to the affected application, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
Virtue Online Test Generator Multiple Security Vulnerabilities
Attackers can use a browser to exploit these issue. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/admin/index.php
http://www.example.com/text.php?tid=null+union+select+1,2,concat(user_name,0x3a,user_pass)+from+admin--
Attackers can use a browser to exploit these issue. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/admin/index.php
http://www.example.com/text.php?tid=null+union+select+1,2,concat(user_name,0x3a,user_pass)+from+admin--
Solution / Fix
Virtue Online Test Generator Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Virtue Online Test Generator Multiple Security Vulnerabilities
References:
References:
- Virtue Online Tests Generator Homepage (Virtue Netz)