LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
BID:55822
Info
LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 55822 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4567 CVE-2012-4570 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2012 12:00AM |
| Updated: | Oct 31 2012 07:20PM |
| Credit: | Raphael Geissert |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
LetoDMS is prone to multiple cross-site scripting and SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
LetoDMS versions prior to 3.3.8 are vulnerable.
LetoDMS is prone to multiple cross-site scripting and SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
LetoDMS versions prior to 3.3.8 are vulnerable.
Exploit / POC
LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
LetoDMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- LetoDMS Homepage (LetoDMS)