Ovidentia Multiple Input Validation Vulnerabilities
BID:61936
Info
Ovidentia Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 61936 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2013 12:00AM |
| Updated: | Aug 22 2013 12:00AM |
| Credit: | Gjoko Krstic |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Ovidentia Multiple Input Validation Vulnerabilities
Ovidentia is prone to an SQL-injection vulnerability, multiple cross-site scripting vulnerabilities and multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Successful exploits could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, or control how the site is rendered to the user; other attacks are also possible.
Ovidentia 7.9.4 is vulnerable; other versions may also be affected.
Ovidentia is prone to an SQL-injection vulnerability, multiple cross-site scripting vulnerabilities and multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Successful exploits could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, execute HTML and script code in the context of the affected site, or control how the site is rendered to the user; other attacks are also possible.
Ovidentia 7.9.4 is vulnerable; other versions may also be affected.
Exploit / POC
Ovidentia Multiple Input Validation Vulnerabilities
An attacker can exploit these issues using a web browser. Attackers must trick a victim into following a malicious URI to exploit cross-site scripting issues.
The following example inputs are available:
An attacker can exploit these issues using a web browser. Attackers must trick a victim into following a malicious URI to exploit cross-site scripting issues.
The following example inputs are available:
Solution / Fix
Ovidentia Multiple Input Validation Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].