[NEWS] E-Data Remote Code Inclusion
From: SecuriTeam (support_at_securiteam.com)
Date: 03/31/05
- Previous message: SecuriTeam: "[UNIX] E-Xoops Easy SQL Injection and Cross Site Scripting"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 31 Mar 2005 10:26:27 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
E-Data Remote Code Inclusion
------------------------------------------------------------------------
SUMMARY
" <http://www.adventia.com/> E-Data is a powerful e-mail directory and
management application that will enhance your web site by letting visitors
add, change and delete their personal information to a directory."
E-Data has user supplied input fields in search and in the "add to
database" functions. By inputting a query keyword followed by a malicious
script, subsequent search may find the keyword that contains the malicious
script. Futher the malicious script contained within the keyword will be
executed.
DETAILS
Vulnerable Systems:
* E-Data version 2.0
Following module is vulnerable:
http://www.adventia.com/cgi-bin/dir.pl
Proof of Concept:
The vendor has a demo site, PoC is in the database, just goto the "demo
URL" and enter "qwerty" in search box demo URL:
<http://www.adventia.com/cgi-bin/dir.pl>
http://www.adventia.com/cgi-bin/dir.pl
 
ADDITIONAL INFORMATION
The information has been provided by <mailto:se_cur_ity@hotmail.com>
Morning Wood.
This vulnerability was discovered by: Donnie Werner from
<http://exploitlabs.com> exploitlabs.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[UNIX] E-Xoops Easy SQL Injection and Cross Site Scripting"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [UNIX] Multiple Vulnerabilities in Phorum (common.php, common.php, login.php, register.php)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Phorum is "an Open Source
web based discussion ... An XSS vulnerability exists in the script 'common.php' that allows
... By sending a HTTP/POST variable to any Phorum script, ... (Securiteam) - [UNIX] Mantis Bug Tracker Multiple Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... any HTML or script code
can be injected. ... * Another XSS vulnerability can be found in the signup.php script
(ex.: ... there is also a remote PHP code execution in the system. ... (Securiteam) - [UNIX] Multiple Vulnerabilities in Psychoblogger CMS Package
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... There is a Cross-Site-Scripting
vulnerability in the script ... Another SQL-Injection vulnerability exists in the comments.php
script, ... This string manipulates the SQL query into looking something like this:
... (Securiteam) - [NT] Snitz Forum 2000 Cross Site Scripting In User Registration Form
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... A cross site scripting vulnerability
has been found in the user ... When registering a new account the register.asp script fails
to properly ... Vendor Status: ... (Securiteam) - [NEWS] Multiple HP Web JetAdmin Vulnerabilities (DoS, Upload, Write, Read, Command Execution)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... script, used in conjunction
with other vulnerable files allow us to use ... File reading vulnerability as well as HTS
script injection ... can create files in the Administrators startup folder. ...
(Securiteam)