IP.Board And IP.Nexus Arbitrary File Include and Cross Site Scripting Vulnerabilities
BID:67164
Info
IP.Board And IP.Nexus Arbitrary File Include and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 67164 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3149 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2014 12:00AM |
| Updated: | Jul 03 2014 12:14AM |
| Credit: | sijad and Christian Schneider |
| Vulnerable: |
Invision Power Services Invision Power Board 3.3.1 Invision Power Services Invision Power Board 3.3 |
| Not Vulnerable: | |
Discussion
IP.Board And IP.Nexus Arbitrary File Include and Cross Site Scripting Vulnerabilities
IP.Board and IP.Nexus are prone to an arbitrary file-include vulnerability and cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the web server process.
IP.Board and IP.Nexus are prone to an arbitrary file-include vulnerability and cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the web server process.
Exploit / POC
IP.Board And IP.Nexus Arbitrary File Include and Cross Site Scripting Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues through a browser. To exploit a cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
IP.Board And IP.Nexus Arbitrary File Include and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IP.Board And IP.Nexus Arbitrary File Include and Cross Site Scripting Vulnerabilities
References:
References: