BugTracker.NET Multiple Security Vulnerabilities
BID:56566
Info
BugTracker.NET Multiple Security Vulnerabilities
| Bugtraq ID: | 56566 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2012 12:00AM |
| Updated: | Nov 15 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Bugtracker.NET Bugtracker.NET 3.5.8 |
| Not Vulnerable: |
Bugtracker.NET Bugtracker.NET 3.5.9 |
Discussion
BugTracker.NET Multiple Security Vulnerabilities
BugTracker.NET is prone to multiple SQL-injection, information-disclosure, cross-site scripting, and HTTP response-splitting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to harvest sensitive information, exploit latent vulnerabilities in the underlying database, influence or misrepresent how web content is served, cached, or interpreted, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
BugTracker.NET 3.5.8 is vulnerable; other versions may also be affected.
BugTracker.NET is prone to multiple SQL-injection, information-disclosure, cross-site scripting, and HTTP response-splitting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to harvest sensitive information, exploit latent vulnerabilities in the underlying database, influence or misrepresent how web content is served, cached, or interpreted, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
BugTracker.NET 3.5.8 is vulnerable; other versions may also be affected.
Exploit / POC
BugTracker.NET Multiple Security Vulnerabilities
An attacker can exploit these issues with a web browser.
An attacker can exploit these issues with a web browser.