Transferable Remote Multiple Security Vulnerabilities
BID:57915
Info
Transferable Remote Multiple Security Vulnerabilities
| Bugtraq ID: | 57915 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2013 12:00AM |
| Updated: | Feb 13 2013 12:00AM |
| Credit: | Benjamin Kunz Mejri and Chokri Ben Achour |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Transferable Remote Multiple Security Vulnerabilities
Transferable is prone to a local file-include vulnerability, multiple cross-site scripting vulnerabilities, multiple HTML-injection vulnerabilities, and a command-injection vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker can exploit these issues to execute arbitrary commands with the privileges of the user running the application, obtain potentially sensitive information, execute arbitrary local scripts in the context of the Web server process, and execute attacker-supplied HTML and script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user
Transferable Remote 1.01 is vulnerable; other versions may also be affected.
Transferable is prone to a local file-include vulnerability, multiple cross-site scripting vulnerabilities, multiple HTML-injection vulnerabilities, and a command-injection vulnerability because it fails to properly sanitize user-supplied input.
A remote attacker can exploit these issues to execute arbitrary commands with the privileges of the user running the application, obtain potentially sensitive information, execute arbitrary local scripts in the context of the Web server process, and execute attacker-supplied HTML and script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user
Transferable Remote 1.01 is vulnerable; other versions may also be affected.
Exploit / POC
Transferable Remote Multiple Security Vulnerabilities
Attackers can exploit these issues with a browser.
Attackers can exploit these issues with a browser.