Domain Technologie Control Multiple Vulnerabilities
BID:49267
Info
Domain Technologie Control Multiple Vulnerabilities
| Bugtraq ID: | 49267 |
| Class: | Unknown |
| CVE: |
CVE-2011-3195 CVE-2011-3196 CVE-2011-3197 CVE-2011-3198 CVE-2011-3199 CVE-2011-5275 CVE-2011-5272 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 22 2011 12:00AM |
| Updated: | Jul 21 2014 12:30AM |
| Credit: | Ansgar Burchardt and Mike O'Connor |
| Vulnerable: |
Domain Technologie Control Domain Technologie Control 0.34 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Domain Technologie Control Domain Technologie Control 0.34.1 |
Discussion
Domain Technologie Control Multiple Vulnerabilities
Domain Technologie Control is prone to the following vulnerabilities:
1. A command-injection vulnerability.
2. An information-disclosure vulnerability.
3. Multiple SQL-injection vulnerabilities.
4. A local file-include vulnerability.
5. A cross-site scripting vulnerability.
6. A privilege-escalation vulnerability.
Exploiting these issues can allow attackers to execute arbitrary commands in the context of the application, obtain sensitive information that may aid in further attacks, manipulate the SQL query logic to carry out unauthorized actions on the underlying database, view and execute arbitrary local files in the context of the webserver process, and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site (which may allow the attacker to steal cookie-based authentication credentials and gain elevated privileges on the affected computer).
Domain Technologie Control is prone to the following vulnerabilities:
1. A command-injection vulnerability.
2. An information-disclosure vulnerability.
3. Multiple SQL-injection vulnerabilities.
4. A local file-include vulnerability.
5. A cross-site scripting vulnerability.
6. A privilege-escalation vulnerability.
Exploiting these issues can allow attackers to execute arbitrary commands in the context of the application, obtain sensitive information that may aid in further attacks, manipulate the SQL query logic to carry out unauthorized actions on the underlying database, view and execute arbitrary local files in the context of the webserver process, and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site (which may allow the attacker to steal cookie-based authentication credentials and gain elevated privileges on the affected computer).
Exploit / POC
Domain Technologie Control Multiple Vulnerabilities
An attacker can use readily available tools to exploit these issues. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can use readily available tools to exploit these issues. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
Domain Technologie Control Multiple Vulnerabilities
Solution:
A vendor-supplied patch is available. Please see the references for more information.
Solution:
A vendor-supplied patch is available. Please see the references for more information.