Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.900883
Kategorie:Web application abuses
Titel:MCshoutbox Multiple SQL Injection and XSS Vulnerabilities
Zusammenfassung:This host is running MCshoutbox and is prone to multiple SQL; Injection and Cross-Site Scripting vulnerabilities.
Beschreibung:Summary:
This host is running MCshoutbox and is prone to multiple SQL
Injection and Cross-Site Scripting vulnerabilities.

Vulnerability Insight:
- Input passed via the 'loginerror' to admin_login.php is not
properly sanitised before being returned to the user. This can be exploited to execute arbitrary
HTML and script code in a user's browser session in the context of an affected site.

- Input passed via the 'username' and 'password' parameters to scr_login.php
is not properly sanitised before being used in an SQL query. This can be
exploited to manipulate SQL queries by injecting arbitrary SQL code.

- The application does not properly check extensions of uploaded 'smilie'
image files. This can be exploited to upload and execute arbitrary PHP code.

Vulnerability Impact:
Successful exploitation will allow attacker to bypass the
authentication mechanism when 'magic_quotes_gpc' is disabled or can cause arbitrary code
execution by uploading the shell code in the context of the web application.

Affected Software/OS:
MCshoutbox version 1.1 on all running platform

Solution:
No known solution was made available for at least one year since the disclosure
of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer
release, disable respective features, remove the product or replace the product by another one.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-3714
http://www.exploit-db.com/exploits/9205
http://osvdb.org/56062
http://secunia.com/advisories/35885
http://www.vupen.com/english/advisories/2009/1961
XForce ISS Database: mcshoutbox-adminlogin-xss(51862)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51862
Common Vulnerability Exposure (CVE) ID: CVE-2009-3715
http://osvdb.org/56063
XForce ISS Database: mcshoutbox-scrlogin-sql-injection(51863)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51863
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.