Time and Expense Management System Multiple Security Vulnerabilities
BID:47688
Info
Time and Expense Management System Multiple Security Vulnerabilities
| Bugtraq ID: | 47688 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 02 2011 12:00AM |
| Updated: | May 02 2011 12:00AM |
| Credit: | AutoSec Tools |
| Vulnerable: |
Initechs Time and Expense Management System 1.6 |
| Not Vulnerable: | |
Discussion
Time and Expense Management System Multiple Security Vulnerabilities
Time and Expense Management System is prone to multiple security vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Attackers may exploit these issues to upload and execute arbitrary PHP shell code in the context of the webserver process, steal cookie-based authentication information, execute arbitrary client-side scripts in the context of the browser, obtain sensitive information, or execute arbitrary commands in the context of the webserver. Other attacks are also possible.
Time and Expense Management System 1.6.0 is vulnerable; other versions may also be affected.
Time and Expense Management System is prone to multiple security vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Attackers may exploit these issues to upload and execute arbitrary PHP shell code in the context of the webserver process, steal cookie-based authentication information, execute arbitrary client-side scripts in the context of the browser, obtain sensitive information, or execute arbitrary commands in the context of the webserver. Other attacks are also possible.
Time and Expense Management System 1.6.0 is vulnerable; other versions may also be affected.
Exploit / POC
Time and Expense Management System Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI and exploits are available:
http://www.example.com/tems/lookup.php?form=a%28%29;}alert%280%29;{//
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI and exploits are available:
http://www.example.com/tems/lookup.php?form=a%28%29;}alert%280%29;{//
Solution / Fix
Time and Expense Management System Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].