eFront Multiple Cross Site Scripting and SQL Injection Vulnerabilities
BID:50492
Info
eFront Multiple Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 50492 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2011 12:00AM |
| Updated: | Nov 02 2011 12:00AM |
| Credit: | High-Tech Bridge SA Security Research Lab |
| Vulnerable: |
eFront eFront 3.6.10 Build 11944 eFront eFront 3.6.2 eFront eFront 3.6.1 eFront eFront 3.5.5 eFront eFront 3.6.9 build 10653 eFront eFront 3.6.9 eFront eFront 3.6.3 build 7400 eFront eFront 3.6.10 eFront eFront 3.6 |
| Not Vulnerable: |
eFront eFront 3.6.10 Build 12151 |
Discussion
eFront Multiple Cross Site Scripting and SQL Injection Vulnerabilities
eFront is prone to multiple cross-site scripting and SQL-injection vulnerabilities because the software fails to sufficiently sanitize user-supplied input.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
eFront 3.6.10 build 11944 is vulnerable; other versions may also be affected.
eFront is prone to multiple cross-site scripting and SQL-injection vulnerabilities because the software fails to sufficiently sanitize user-supplied input.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
eFront 3.6.10 build 11944 is vulnerable; other versions may also be affected.
Exploit / POC
eFront Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
The following example URIs are available:
Solution / Fix
eFront Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
eFront Multiple Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- eFront Homepage (eFront)
- High-Tech Bridge SA Multiple vulnerabilities in Efront (High-Tech Bridge SA Security Research Lab)