Secunia Advisory SA17383Ringtail CaseBook Multiple Vulnerabilities
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A weakness and some vulnerabilities have been reported in Ringtail CaseBook, which can be exploited by malicious people to gain knowledge of certain information and conduct cross-site scripting attacks. 1) An error caused due to the application returning different error responses depending on whether or not a valid username is supplied, can can be exploited to enumerate valid usernames. 2) Input passed to the "user" parameter in "login.asp" isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. 3) Input passed to the "users" parameter in "login.asp" isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. 4) Input passed to the "inline" parameter in "riv_install.asp" is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Weakness #1 and vulnerability #2 are reported in version 6.1.0. Vulnerabilities #3 and #4 are reported in version 6.1.1 rp2. Other versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
255 views | ![]() |
| Limny Multiple Vulnerabilities | |
355 views | ![]() |
| Ubuntu update for thunderbird | |
252 views | ![]() |
| Debian update for php5 | |