Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Ourvideo CMS Multiple Input Validation Vulnerabilities

Ourvideo CMS is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input. These vulnerabilities include two remote file-include issues, a local file-include issue, and two cross-site scripting issues.

Attackers can exploit the remote file-include issues to execute arbitrary script code in the context of the webserver process. They can exploit the local file-include issue to execute arbitrary local scripts in the context of the webserver and access sensitive information. They can leverage the cross-site scripting issues to steal cookie-based authentication credentials. Other attacks are possible; information harvested can aid in further attacks.

Ourvideo CMS 9.5 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus