Quack Chat Multiple Security Vulnerabilities
BID:61803
Info
Quack Chat Multiple Security Vulnerabilities
| Bugtraq ID: | 61803 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2013 12:00AM |
| Updated: | Aug 15 2013 12:00AM |
| Credit: | Dylan Irzi |
| Vulnerable: |
Quack Chat Quack Chat 1.0 |
| Not Vulnerable: | |
Discussion
Quack Chat Multiple Security Vulnerabilities
Quack Chat is prone to multiple security vulnerabilities.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; other attacks may also be possible.
Quack Chat 1.0 is vulnerable; other versions may also be affected.
Quack Chat is prone to multiple security vulnerabilities.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; other attacks may also be possible.
Quack Chat 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Quack Chat Multiple Security Vulnerabilities
An attacker can exploit these issues using a web browser. To exploit multiple cross-site scripting vulnerabilities an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
The following example URI is available:
www.example.com/qc_admin/index.php?p=history&page=2%22%22%3E%3Cimg%20src=x%20onerror=prompt%28/XSS/%29;%3E%3E
An attacker can exploit these issues using a web browser. To exploit multiple cross-site scripting vulnerabilities an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
The following example URI is available:
www.example.com/qc_admin/index.php?p=history&page=2%22%22%3E%3Cimg%20src=x%20onerror=prompt%28/XSS/%29;%3E%3E
Solution / Fix
Quack Chat Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].