New User, Welcome!     Login

<< Previous Next >>

penetration testing

[Onapsis Security Advisory 2010-009] Oracle Virtual Server Agent Remote Command Execution

their information and decreasing financial fraud risks.

Onapsis is built upon a team of world-renowned experts in the SAP security field, with several years of experience in the assessment and protection of
critical platforms in world-wide customers, such as Fortune-500 companies and governmental entities.

Our star product, Onapsis X1, enables our customers to perform automated Security & Compliance Audits, Vulnerability Assessments and Penetration Tests
over their SAP platform, helping them enforce compliance requirements, decrease financial fraud risks an reduce audit costs drastically.

Some of our featured services include SAP Penetration Testing, SAP Gateway & RFC security, SAP Enterprise Portal security assessment, Security Support
for SAP Implementations and Upgrades, SAP System Hardening and SAP Technical Security Audits.


LFI in DZCP

Vulnerable Version: 1.5.4 
Vendor Notification: 13 October 2010 
Vulnerability Type: Local File Inclusion
Status: Fixed by Vendor
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in [prefix]_language variable from cookie.

The following PoC is available:

HTB22872: Path disclosure in Cool Video Gallery wordpress plugin

Vendor: Praveen Rajan ( http://wordpress.org/extend/plugins/cool-video-gallery/ ) 
Vulnerable Version: 1.3
Vendor Notification: 22 February 2011 
Vulnerability Type: Path disclosure
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/wp-content/plugins/cool-video-gallery/admin/gallery-sort.php" scripts, it's possible to generate an error that will reveal the full path of the script.
A remote user can determine the full path to the web root directory and other potentially sensitive information.


XSS vulnerability in Atutor edit content folder

Vulnerable Version: 1.0
Vendor Notification: 01 September 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/mods/_core/editor/edit_content_folder.php" script to properly sanitize user-supplied input in "cid" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

SQL injection vulnerability in CMSQLite

Vulnerable Version: 1.3 and Probably Prior Versions
Vendor Notification: 29 June 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/admin/editArticle.php" script to properly sanitize user-supplied input in "id" variable. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.

Attacker can use browser to exploit this vulnerability. The following PoC is available:

XSRF (CSRF) in phpwcms

Vulnerable Version: 1.4.5 and Probably Prior Versions
Vendor Notification: 01 July 2010 
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "phpwcms.php" script to properly verify the source of HTTP request.

Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSRF (CSRF) in Wolf CMS

Vulnerable Version: 0.6.0b and probably prior versions
Vendor Notification: 09 November 2010 
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Status: Fixed by Vendor
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "wolf/app/controllers/UserController.php" script to properly verify the source of HTTP request.

Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Path disclosure in IceBB

Vulnerable Version: 1.0-rc10
Vendor Notification: 02 November 2010 
Vulnerability Type: Path disclosure
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists in the "/modules/make_image.php" script.
A remote user can determine the full path to the web root directory and other potentially sensitive information.


HTB22843: Path disclosure in GD Star Rating wordpress plugin

Vulnerable Version: 1.9.7
Vendor Notification: 08 February 2011 
Vulnerability Type: Path disclosure
Status: Awaiting Vendor Solution
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/wp-content/plugins/gd-star-rating/widgets/widget_top.php" script, it's possible to generate an error that will reveal the full path of the script.
A remote user can determine the full path to the web root directory and other potentially sensitive information.


Re: XSS vulnerability in Auto CMS

Figured I would share this since it doesn't appear this was disclosed on 
Bugtraq. I'd also point out that this really makes people question your 
auditing and ethical hacking ability. If you find XSS and pedestrian SQLi, 
but miss code execution, it doesn't bode well for your customers.

: Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 



HTB22814: XSS vulnerability in ViArt Shop

Vulnerable Version: Enterprise v.4.0.5
Vendor Notification: 25 January 2011 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/admin/admin_product.php" script to properly sanitize user-supplied input in "item_id" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSRF (CSRF) in Open blog

Vulnerable Version: 1.2.1 and Probably Prior Versions
Vendor Notification: 22 July 2010 
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/application/modules/admin/controllers/users.php" script to properly verify the source of HTTP request.

Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

HTB22848: XSS in Mingle Forum wordpress plugin

Vendor: Cartpauj ( http://cartpauj.com/ ) 
Vulnerable Version: 1.0.28
Vendor Notification: 15 February 2011 
Vulnerability Type: XSS (Cross Site Scripting)
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.
Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.


XSS vulnerability in Entrans

Vulnerable Version: 0.3.2 and Probably Prior Versions
Vendor Notification: 13 September 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Fixed by Vendor
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "search.php" script to properly sanitize user-supplied input in "query" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

HTB22789: Path disclousure in Pivotx

Vulnerable Version: 2.2.0
Vendor Notification: 11 January 2011 
Vulnerability Type: Path disclosure
Status: Awaiting Vendor Solution
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/includes/ping.php" & "/includes/spamping.php" scripts, it's possible to generate an error that will reveal the full path of the script.
A remote user can determine the full path to the web root directory and other potentially sensitive information.


HTB22880: XSS vulnerability in CosmoShop

Vulnerable Version: ePRO V10.05.00
Vendor Notification: 24 February 2011 
Vulnerability Type: Stored XSS (Cross Site Scripting)
Status: Fixed by Vendor
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "cgi-bin/admin/edit_startseitentext.cgi" script to properly sanitize user-supplied input in "text-de" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS in CLANSPHERE

Vulnerable Version: 2010.0 Final
Vendor Notification: 02 November 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Fixed by Vendor
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/mods/gallery/print_now.php" script to properly sanitize user-supplied input in "pic" and "size" variables. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

SQL Injection in phpMySport

Vulnerable Version: 1.4
Vendor Notification: 21 December 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in "name" variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.


SQL injection in eoCMS

Vulnerable Version: 0.9.04
Vendor Notification: 21 October 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "index.php" script to properly sanitize user-supplied input in eocms value from cookies.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.


XSS vulnerability in ImpressCMS

Vulnerable Version: 1.2.3 Final and probably prior versions
Vendor Notification: 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "/modules/content/admin/content.php" script to properly sanitize user-supplied input in "quicksearch_ContentContent" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in Edit-X CMS

Vulnerable Version: Current at 27.07.2010 and Probably Prior Versions
Vendor Notification: 27 July 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "index.php" script to properly sanitize user-supplied input in "search_text" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

LFI in Exponent CMS

Vulnerable Version: 2.0.0pr2
Vendor Notification: 22 November 2010 
Vulnerability Type: Local File Inclusion
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/rss.php" script to properly sanitize user-supplied input in module variable.

The following PoC is available:

XSRF (CSRF) in CMScout

Vulnerable Version: 2.09 and probably prior versions
Vendor Notification: 25 November 2010 
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "admin.php" script to properly verify the source of HTTP request.

Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

XSS vulnerability in Theeta CMS

Vulnerable Version: 0.0
Vendor Notification: 12 July 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "forum.php" script to properly sanitize user-supplied input in "forum" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Re: XSRF (CSRF) in Zimplit

: Vendor: Zimplit Ltd. ( http://www.zimplit.com/ ) 
: Vulnerable Version: 3.0 and Probably Prior Versions
: Vendor Notification: 15 September 2010 
: Vulnerability Type: CSRF (Cross-Site Request Forgery)
: Risk level: Low 
: Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 
: 
: Vulnerability Details:
: The vulnerability exists due to failure in the "zimplit.php" script to properly verify the source of HTTP request.
: 
: Successful exploitation of this vulnerability could result in a 

XSS vulnerability in Spitfire

Vulnerable Version: 1.0.336 and Probably Prior Versions
Vendor Notification: 08 July 2010 
Vulnerability Type: XSS (Cross Site Scripting)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.
"tpl_element_settings_action.php" script to properly sanitize user-supplied input in "value[description]" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.


SQL injection in KaiBB

Vulnerable Version: 1.0.1
Vendor Notification: 09 December 2010 
Vulnerability Type: SQL Injection
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in "term" variable.
Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.


Directory Traversal in FTPGetter

Vulnerable Version: 3.51.0.05 and Probably Prior Versions
Vendor Notification: 05 August 2010 
Vulnerability Type: File Content Disclosure
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
When exploited, this vulnerability allows an anonymous attacker to write files to specified locations on a user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences that are received from an FTP server, for example

HTB22831: XSS vulnerability in Gollos

Vendor: Gollos ( http://www.gollos.com/ ) 
Vulnerable Version: 2.8 and probably prior versions
Vendor Notification: 01 February 2011 
Vulnerability Type: XSS (Cross Site Scripting)
Risk level: Medium 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
User can execute arbitrary JavaScript code within the vulnerable application.

The vulnerability exists due to failure in the "product/list.aspx" script to properly sanitize user-supplied input in "q" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.

Path disclosure in HTML-EDIT CMS

Vulnerable Version: 3.1.8
Vendor Notification: 02 December 2010 
Vulnerability Type: Path disclosure
Status: Fixed by Vendor
Risk level: Low 
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/) 

Vulnerability Details:
A remote user can determine the full path to the web root directory and other potentially sensitive information.

Attacker can use browser to exploit this vulnerability. The following PoC is available:

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!