Trixbox Multiple Security Vulnerabilities
BID:68720
Info
Trixbox Multiple Security Vulnerabilities
| Bugtraq ID: | 68720 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-5109 CVE-2014-5110 CVE-2014-5111 CVE-2014-5112 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2014 12:00AM |
| Updated: | Oct 17 2014 07:04PM |
| Credit: | AtT4CKxT3rR0r1ST |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Trixbox Multiple Security Vulnerabilities
Trixbox is prone to the following security vulnerabilities:
1. An SQL-injection vulnerability
2. A cross-site scripting vulnerability
3. Multiple local file-include vulnerabilities
4. A remote code-execution vulnerability
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, exploit latent vulnerabilities in the underlying database or perform certain unauthorized actions and gain access to the affected application.
Trixbox is prone to the following security vulnerabilities:
1. An SQL-injection vulnerability
2. A cross-site scripting vulnerability
3. Multiple local file-include vulnerabilities
4. A remote code-execution vulnerability
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials, exploit latent vulnerabilities in the underlying database or perform certain unauthorized actions and gain access to the affected application.
Exploit / POC
Trixbox Multiple Security Vulnerabilities
Attackers can exploit these issues using a browser or readily available tools. To exploit the cross-site scripting a issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues using a browser or readily available tools. To exploit the cross-site scripting a issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Trixbox Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Trixbox Multiple Security Vulnerabilities
References:
References: