FleetCommander Multiple Remote Security Vulnerabilities
BID:56427
Info
FleetCommander Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 56427 |
| Class: | Unknown |
| CVE: |
CVE-2012-4941 CVE-2012-4942 CVE-2012-4943 CVE-2012-4944 CVE-2012-4945 CVE-2012-4946 CVE-2012-4947 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2012 12:00AM |
| Updated: | Nov 07 2012 12:00AM |
| Credit: | Travis Lee |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
FleetCommander Multiple Remote Security Vulnerabilities
FleetCommander is prone to multiple remote security vulnerabilities, including:
1. A cross-site request forgery vulnerability
2. Multiple HTML-injection vulnerabilities
3. Multiple SQL-injection vulnerabilities
4. Multiple command-injection vulnerabilities
5. Multiple information-disclosure vulnerabilities
6. A password encryption weakness
7. Multiple arbitrary file-upload vulnerabilities
Attackers can exploit these issues to disclose sensitive information, upload arbitrary code, and run it in the context of the web server process, execute arbitrary command, execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site, to perform certain unauthorized actions, access or modify data, and exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
FleetCommander is prone to multiple remote security vulnerabilities, including:
1. A cross-site request forgery vulnerability
2. Multiple HTML-injection vulnerabilities
3. Multiple SQL-injection vulnerabilities
4. Multiple command-injection vulnerabilities
5. Multiple information-disclosure vulnerabilities
6. A password encryption weakness
7. Multiple arbitrary file-upload vulnerabilities
Attackers can exploit these issues to disclose sensitive information, upload arbitrary code, and run it in the context of the web server process, execute arbitrary command, execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site, to perform certain unauthorized actions, access or modify data, and exploit latent vulnerabilities in the underlying database. Other attacks may also be possible.
Exploit / POC
FleetCommander Multiple Remote Security Vulnerabilities
Attackers can exploit these issues with a browser. To exploit the cross-site request-forgery issue the attacker must entice an unsuspecting victim into viewing a malicious webpage.
Attackers can exploit these issues with a browser. To exploit the cross-site request-forgery issue the attacker must entice an unsuspecting victim into viewing a malicious webpage.
Solution / Fix
FleetCommander Multiple Remote Security Vulnerabilities
Solution:
The vendor released an update. Please see the references for more information.
Solution:
The vendor released an update. Please see the references for more information.
References
FleetCommander Multiple Remote Security Vulnerabilities
References:
References: