Froxler Multiple SQL Injection and HTML Injection Vulnerabilities
BID:47079
Info
Froxler Multiple SQL Injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 47079 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 29 2011 12:00AM |
| Updated: | Mar 29 2011 12:00AM |
| Credit: | tomreyn |
| Vulnerable: |
Froxler Froxler 0.9.18.1 Froxler Froxler 0.9.18 |
| Not Vulnerable: |
Froxler Froxler 0.9.19 |
Discussion
Froxler Multiple SQL Injection and HTML Injection Vulnerabilities
Froxler is prone to multiple SQL-injection and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage the HTML-injection issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.
The attacker may exploit the SQL-injection issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Froxler 0.9.19 are vulnerable.
Froxler is prone to multiple SQL-injection and HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage the HTML-injection issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials, control how the site is viewed, and launch other attacks.
The attacker may exploit the SQL-injection issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Froxler 0.9.19 are vulnerable.
Exploit / POC
Froxler Multiple SQL Injection and HTML Injection Vulnerabilities
An attacker can exploit these issues with a web browser.
An attacker can exploit these issues with a web browser.
Solution / Fix
Froxler Multiple SQL Injection and HTML Injection Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Froxler Multiple SQL Injection and HTML Injection Vulnerabilities
References:
References:
- Fixing a XSS - vulnerability discovered by tomreyn (Florian Aders)
- Fixing SQL-incjection found by tomreyn and general ticket-search, fixes #674 (Florian Aders)
- Froxler Homepage (Froxler)
- Release: Froxlor 0.9.19 Security bugfix release (Froxler)