AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
August 21, 2008, 10:06:27 AM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 3455 Members
Latest Member: FreeOemSoftwarea
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  Resellers  |  Security Alerts  |  Topic: Modern Bill 4.3.0 and prior Vulnerability 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Modern Bill 4.3.0 and prior Vulnerability  (Read 2091 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Modern Bill 4.3.0 and prior Vulnerability
« on: April 11, 2005, 09:37:35 PM »

 FrSIRT Advisory : FrSIRT/ADV-2005-0329
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : High
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-04-11

 * Technical Description *

Two vulnerabilities were identified in ModernBill, which may be exploited by remote attackers to compromise a vulnerable server or conduct Cross Site Scripting attacks.

- The first flaw is due to an input validation error in the "news.php" script when handling a specially crafted "DIR" variable, which may be exploited by a remote attacker to include a malicious PHP script and execute arbitrary commands with the privileges of the web server.

- The second vulnerability is due to an input validation error in the "orderwiz.php" file when handling specially crafted "c_code" or "aid" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.

 * Affected Products *

ModernBill version 4.3.0 and prior

 * Solution *

ModernBill version 4.3.1 :
http://www.modernbill.com/

 * References *

http://www.frsirt.com/english/advisories/2005/0329
http://www.gulftech.org/?node=research&article_id=00067-04102005

 * Credits *

Vulnerability reported by James Bercegay
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  Resellers  |  Security Alerts  |  Topic: Modern Bill 4.3.0 and prior Vulnerability « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!