All vulnerabilities published here were discovered automatically by full-featured commercial version of MaxPatrol. Free Demo version available for download has limitations in detection of such vulnerabilities.
1. A remote user may be able to execute arbitrary SQL commands on the underlying database.
2. Execute arbitrary HTML and script code in a users browser session in context of a vulnerable site.
Exploitation of this vulnerability allows remote attackers to mount various kinds of attacks. For example: Cross-Site Scripting XSS, Web Cache Poisoning deface, Browser cache poisoning, Hijacking pages with user-specific information and etc...
Input passed to the "Location" parameter is not properly sanitised. This can be exploited to inject malicious characters into HTTP headers and may allow execution of arbitrary HTML and script code in a user's browser session in context of an affected site.
Request:
http://[server]/phorum5/search.php?forum_id=0&search=1&body=%0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.0%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:%2034%0d%0a%0d%0a<html>Scanned by PTsecurity</html>%0d%0a&author=1&subject=1&match_forum=ALL&match_type=ALL&match_dates=30
Result:
HTTP/1.1 302 Found Date: Tue, 01 Mar 2005 12:33:53 GMT Server: Apache/1.3.31 (Unix) PHP/4.3.10 X-Powered-By: PHP/4.3.10 Location: http://[server]/phorum5/search.php?0,search=1,page=1,match_type=ALL,match_dates=30,match_forum=ALL,body= Content-Length: 0
HTTP/1.0 200 OK Content-Type: text/html Content-Length: 34
<html>Scanned by PTsecurity</html> ,author=1,subject=1 Connection: close Content-Type: text/html
<...>
The vulnerability has been reported in Phorum version 5.0.14. Other versions may also be affected.
Impact
Exploitation of this vulnerability allows remote attackers to mount various kinds of attacks. For example: Cross-Site Scripting XSS, Web Cache Poisoning deface, Browser cache poisoning, Hijacking pages with user-specific information and etc...
Solution
Update to version 5.0.15a.
http://phorum.org/story.php?48
http://phorum.org/downloads/phorum-5.0.15a.tar.gz
SQL-injection in Ikonboard 3.1.x
Date: 16.12.04
Application: Ikonboard 3.1.x 3.1.0, 3.1.1, 3.1.2 and 3.1.3.
<...> <br /> <b>Warning</b>: fopen(system/help/1.txt): failed to open stream: No such file or directory in <b>/home/neocrome/public_html/system/core/plug.inc.php</b> on line <b>266</b><br/>
Result: <...> ion_start(): The session id contains invalid characters, valid characters are only a-z, A-Z and 0-9 in <b>/home/neocrome/public_html/system/common.php</b> on line <b>169</b><br />
<...>
Impact
A remote user can execute SQL commands on the underlying database.
Solution
Check for update: http://www.neocrome.net/index.php?msingle&id91.
An input validation vulnerability was discovered in Phorum 5.0.11. A remote user can conduct SQL injection.
1. SQL injection example
/read.php?1,[SQL CODE HERE],newer
Impact
A remote user can access the target users cookies including authentication cookies. A remote user may be able to execute arbitrary SQL commands on the underlying database.
Solution
Check for new version or update.
Cross Site Scripting, SQL injection and HTTP Response Splitting in Ideal BB 0.1.5.3
A remote user can access the target users cookies including authentication cookies.
A remote user may be able to poison any intermediate web caches with arbitrary content.
A remote user can inject SQL commands.
A remote user can access the tar users cookies including authentication cookies.
A remote user can inject SQL commands to be executed on the underlying database.
Solution
Not available currently.
Cross Site Scripting and SQL injection in Dmxready Site Chassis Manager
A remote user can access the target users cookies including authentication cookies. A remote user can inject SQL commands to be executed on the underlying database.
Solution
Not available currently.
Cross Site Scripting in CyberStrong eShop ASP Shopping Card v4.6
A remote user can access the target users cookies including authentication cookies. A remote user can cause SQL commands to be executed by the underlying database.
Solution
Not available currently.
SQL injection, HTTP Response Splitting, Cross Site Scripting Vulnerabilities in w-Agora Forum
Multiple vulnerabilities were found in w-Agora forum. A remote user can conduct SQL injection attack, HTTP Response Splitting and Cross Site Scripting attack.
A remote user can access the target users cookies including authentication cookies. A remote user can cause SQL commands to be executed by the underlying database. A remote user may be able to poison any intermediate web caches with arbitrary content.
Solution
Check for new version or update on developers site.
Multiple SQL-Injection and Cross Site Scripting Vulnerabilities in AliveSites Forum 2.0
A remote user can access the target users cookies including authentication cookies.
A remote user can cause SQL commands to be executed by the underlying database.
Solution
Not available currently.
Multiple SQL-Injection and Cross Site Scripting Vulnerabilities in Gosmart4u Message Board
A remote user can access the target users cookies including authentication cookies. A remote user can cause SQL commands to be executed by the underlying database.
Solution
Not available currently.
Multiple Cross Site Scripting and HTTP Response Splitting Vulnerabilities in DCP-Portal
Multiple vulnerabilities was found in DCP-Portal. A remote user can conduct Cross Site Scripting attacks and HTTP Response Splitting attacks. The following scripts are vulnerable:
A remote user can access the target users cookies including authentication cookies. A remote user may be able to poison any intermediate web caches with arbitrary content.