ionCube Loader Wizard 'loader-wizard.php' Multiple Security Vulnerabilities
BID:66531
Info
ionCube Loader Wizard 'loader-wizard.php' Multiple Security Vulnerabilities
| Bugtraq ID: | 66531 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2014 12:00AM |
| Updated: | Mar 30 2014 12:00AM |
| Credit: | Firefart |
| Vulnerable: |
ionCube Loader Wizard 2.45 |
| Not Vulnerable: |
ionCube Loader Wizard 2.46 |
Discussion
ionCube Loader Wizard 'loader-wizard.php' Multiple Security Vulnerabilities
ionCube Loader is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerbility
2. An information-disclosure vulnerabilities
3. An Arbitrary File Disclosure Vulnerability
An attacker can exploit these issues to obtain potentially sensitive information, to view arbitrary files from the local filesystem and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials to launch other attacks.
Versions prior to ionCube Loader 2.46 are vulnerable.
ionCube Loader is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerbility
2. An information-disclosure vulnerabilities
3. An Arbitrary File Disclosure Vulnerability
An attacker can exploit these issues to obtain potentially sensitive information, to view arbitrary files from the local filesystem and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials to launch other attacks.
Versions prior to ionCube Loader 2.46 are vulnerable.
References
ionCube Loader Wizard 'loader-wizard.php' Multiple Security Vulnerabilities
References:
References:
- ionCube Loader Wizard Homepage (ionCube)
- Multiple vulnerabilities in ionCube loader-wizard (firefart)