AllMyGuests Multiple Security Vulnerabilities
BID:70177
Info
AllMyGuests Multiple Security Vulnerabilities
| Bugtraq ID: | 70177 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2014 12:00AM |
| Updated: | Sep 29 2014 12:00AM |
| Credit: | Indoushka |
| Vulnerable: |
Voice Of Web AllMyGuests version 0.4.1 |
| Not Vulnerable: | |
Discussion
AllMyGuests Multiple Security Vulnerabilities
AllMyGuests is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability
2. An SQL-injection vulnerability
3. A security-bypass vulnerability
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and bypass certain security restrictions and perform unauthorized actions.
AllMyGuests 0.4.1 is vulnerable; other versions may also be affected.
AllMyGuests is prone to the following security vulnerabilities:
1. A cross-site scripting vulnerability
2. An SQL-injection vulnerability
3. A security-bypass vulnerability
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and bypass certain security restrictions and perform unauthorized actions.
AllMyGuests 0.4.1 is vulnerable; other versions may also be affected.
Exploit / POC
AllMyGuests Multiple Security Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
AllMyGuests Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].