Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801153
Categoría:Web application abuses
Título:Xoops Celepar <= 2.2.4 Multiple Vulnerabilities - Active Check
Resumen:Xoops Celepar is prone to multiple vulnerabilities.
Descripción:Summary:
Xoops Celepar is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- The flaw exists in 'Qas (aka Quas) module'. Input passed to the 'codigo' parameter in
modules/qas/aviso.php and modules/qas/imprimir.php, and the 'cod_categoria' parameter in
modules/qas/categoria.php is not properly sanitised before being used in an SQL query.

- The flaw exists in 'Qas (aka Quas) module' and 'quiz'module. Input passed to the 'opcao'
parameter to modules/qas/index.php, and via the URL to modules/qas/categoria.php,
modules/qas/index.php, and modules/quiz/cadastro_usuario.php is not properly sanitised before
being returned to the user.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute
arbitrary SQL statements on the vulnerable system, which may allow an attacker to view, add,
modify data, or delete information in the back-end database and also conduct cross-site
scripting.

Affected Software/OS:
Xoops Celepar version 2.2.4 and prior.

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-4698
BugTraq ID: 35820
http://www.securityfocus.com/bid/35820
http://www.exploit-db.com/exploits/9249
http://www.exploit-db.com/exploits/9261
http://osvdb.org/56593
http://www.osvdb.org/56594
http://osvdb.org/56595
http://secunia.com/advisories/35966
XForce ISS Database: celepar-aviso-sql-injection(51985)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51985
Common Vulnerability Exposure (CVE) ID: CVE-2009-4713
http://osvdb.org/56596
http://osvdb.org/56597
Common Vulnerability Exposure (CVE) ID: CVE-2009-4714
http://packetstormsecurity.org/0907-exploits/xoopsceleparquiz-xss.txt
http://www.osvdb.org/56598
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.