ProQuiz Cross Site Scripting, SQL Injection and Remote File Include Vulnerabilities
BID:54976
Info
ProQuiz Cross Site Scripting, SQL Injection and Remote File Include Vulnerabilities
| Bugtraq ID: | 54976 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2012 12:00AM |
| Updated: | Aug 11 2012 12:00AM |
| Credit: | L0n3ly-H34rT |
| Vulnerable: |
ProQuiz ProQuiz 2.0.2 |
| Not Vulnerable: | |
Discussion
ProQuiz Cross Site Scripting, SQL Injection and Remote File Include Vulnerabilities
ProQuiz is prone to multiple input-validation vulnerabilities, including:
1. A cross-site scripting vulnerability
2. Multiple SQL-injection vulnerabilities
3. A remote file-include vulnerability
Exploiting these issues could allow an attacker to execute arbitrary script code and PHP code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ProQuiz 2.0.2 is vulnerable; other versions may also be affected.
ProQuiz is prone to multiple input-validation vulnerabilities, including:
1. A cross-site scripting vulnerability
2. Multiple SQL-injection vulnerabilities
3. A remote file-include vulnerability
Exploiting these issues could allow an attacker to execute arbitrary script code and PHP code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ProQuiz 2.0.2 is vulnerable; other versions may also be affected.
Solution / Fix
ProQuiz Cross Site Scripting, SQL Injection and Remote File Include Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
ProQuiz Cross Site Scripting, SQL Injection and Remote File Include Vulnerabilities
References:
References:
- ProQuiz Sourceforge Page (ProQuiz)