Search:     Advanced search
server monitoring

Episodex Guestbook Multiple Vulnerabilities (Auth Bypass, XSS)

Article ID: 18362
Last updated: 27 Jan, 2009
Views: 11442
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Episodex Guestbook Multiple Vulnerabilities (Auth Bypass, XSS)

Copyright (C) 2005-2009 Josh Zlatin-Amishav

FamilyCGI abuses
Plugin ID18362
Bugtraq ID13692
13693
CVE IDCVE-2005-1684
CVE-2005-1685

Description:

Synopsis :

The remote web server contains an ASP application that is affected by
several issues.

Description :

The remote host is running the Episodex Guestbook, a guestbook written
in ASP.

The version of Episodex installed on the remote host does not validate
input to various fields in the default.asp script before using it to
generate dynamic HTML.

In addition, an unauthenticated remote attacker can edit settings by
accessing the applications admin.asp script directly.

See also :

http://archives.neohapsis.com/archives/bugtraq/2005-05/0249.html

Solution :

Unknown at this time.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
This article was:   Helpful | Not Helpful
Prev   Next
Horde IMP mailbox.php3 Multiple Variable SQL Injection     Plain Old Webserver URI Traversal Arbitrary File Access