Bacula-web 'report.php' Cross Site Scripting and SQL Injection Vulnerabilities
BID:46765
Info
Bacula-web 'report.php' Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 46765 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2011 12:00AM |
| Updated: | Mar 07 2011 12:00AM |
| Credit: | b0telh0 |
| Vulnerable: |
Bacula-Web Bacula-web 5.0.3 Bacula-Web Bacula-web 1.38.9_1 |
| Not Vulnerable: | |
Discussion
Bacula-web 'report.php' Cross Site Scripting and SQL Injection Vulnerabilities
Bacula-web is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Bacula-web 5.0.3 and 1.38.9_1 are vulnerable; other versions may also be affected.
Bacula-web is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Bacula-web 5.0.3 and 1.38.9_1 are vulnerable; other versions may also be affected.
Exploit / POC
Bacula-web 'report.php' Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs and exploit code are available:
http://www.example.com/bacula/report.php?default=1&server=Backup_inc<script>alert("xss")</script>
http://www.example.com/bacula/report.php?default=1&server=Backup_inc' and 1='2 #FALSE
http:/www.example.com/bacula/report.php?default=1&server=Backup_inc' and 1='1 #TRUE
An attacker can exploit these issues through a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example URIs and exploit code are available:
http://www.example.com/bacula/report.php?default=1&server=Backup_inc<script>alert("xss")</script>
http://www.example.com/bacula/report.php?default=1&server=Backup_inc' and 1='2 #FALSE
http:/www.example.com/bacula/report.php?default=1&server=Backup_inc' and 1='1 #TRUE
Solution / Fix
Bacula-web 'report.php' Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Bacula-web 'report.php' Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- Bacula-Web Homepage (Bacula-Web)