|
|
>> BibORB Directory Traversal and Cross Site Scripting Vulnerabilities
|
Several vulnerabilities were identified in BibORB, which may be exploited by attackers to execute arbitrary HTML/Javascript codes, upload arbitrary files, or bypass certain seurity features.
http://vulnerable/bibindex.php?mode=displaysearch&search=<XSS>&sort=ID
http://vulnerable/index.php?mode=result&database_name=../config.php&action=Delete
Affected Products
BibORB version 1.3.2 and earlier
Solution
BibORB 1.3.2 Security Update or to 1.3.3 RC1 :
http://biborb.glymn.net/doku.php
References
http://www.vupen.com/english/advisories/2005/0180
Credits
Vulnerability reported by Patrick Hof
ChangeLog
2005-02-18 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|