WHMCS Multiple Security Vulnerabilities
BID:65080
Info
WHMCS Multiple Security Vulnerabilities
| Bugtraq ID: | 65080 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2014 12:00AM |
| Updated: | Jan 21 2014 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
WHMCS WHMCS 5.2.13 WHMCS WHMCS 5.2.12 WHMCS WHMCS 5.2.11 WHMCS WHMCS 5.2.8 WHMCS WHMCS 5.2.7 WHMCS WHMCS 5.2.1 WHMCS WHMCS 5.2 WHMCS WHMCS 5.2.15 WHMCS WHMCS 5.2.14 |
| Not Vulnerable: |
WHMCS WHMCS 5.2.16 |
Discussion
WHMCS Multiple Security Vulnerabilities
WHMCS is prone to multiple security vulnerabilities including multiple access-bypass vulnerabilities, an unspecified SQL-injection vulnerability, an unspecified cross-site scripting vulnerability, and an unspecified HTTP-header-injection vulnerability.
Exploiting these issues may allow an attacker to perform unauthorized actions, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or insert arbitrary headers into an HTTP response.
Versions prior to WHMCS 5.2.16 are vulnerable.
WHMCS is prone to multiple security vulnerabilities including multiple access-bypass vulnerabilities, an unspecified SQL-injection vulnerability, an unspecified cross-site scripting vulnerability, and an unspecified HTTP-header-injection vulnerability.
Exploiting these issues may allow an attacker to perform unauthorized actions, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or insert arbitrary headers into an HTTP response.
Versions prior to WHMCS 5.2.16 are vulnerable.
Exploit / POC
WHMCS Multiple Security Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can use a browser to exploit these issues. To exploit cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
WHMCS Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
WHMCS Multiple Security Vulnerabilities
References:
References:
- WHMCS Homepage (WHMCS)
- WHMCS Security Advisory TSR-2014-0001 (WHMCS)