PopScript 'index.php' Multiple Input Validation Vulnerabilities
BID:48113
Info
PopScript 'index.php' Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 48113 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 06 2011 12:00AM |
| Updated: | Jun 06 2011 12:00AM |
| Credit: | NassRawI |
| Vulnerable: |
PopScript.com PopScript 0 |
| Not Vulnerable: | |
Discussion
PopScript 'index.php' Multiple Input Validation Vulnerabilities
PopScript is prone to a remote file-include vulnerability, an SQL-injection vulnerability and a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to execute arbitrary local and remote scripts in the context of the webserver process, access or modify data, exploit latent vulnerabilities in the underlying database, or bypass the authentication control.
PopScript is prone to a remote file-include vulnerability, an SQL-injection vulnerability and a local file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to execute arbitrary local and remote scripts in the context of the webserver process, access or modify data, exploit latent vulnerabilities in the underlying database, or bypass the authentication control.
Exploit / POC
PopScript 'index.php' Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/PopScript/index.php?act=inbox&mode=1 [ SQL injection ]
http://www.example.com/index.php?mode=[Shell txt]?&password=nassrawi&remember=ON
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/PopScript/index.php?act=inbox&mode=1 [ SQL injection ]
http://www.example.com/index.php?mode=[Shell txt]?&password=nassrawi&remember=ON
Solution / Fix
PopScript 'index.php' Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PopScript 'index.php' Multiple Input Validation Vulnerabilities
References:
References:
- PopScript Homepage (PopScript.com)
- PopScript Multiple Vulnerabilities ([email protected])