GVI-2010-02 : Multiple vulnerabilities in Open-AudIT
Multiple security issues were discovered which can be categorized as : Lack of Authentication, SQL Injection, Cross-Site Scripting, Local File Include. When the 'Use Passwords' option is activated, Open-AudIT requires a user and password to be provided to access the web administrative interface. However, several scripts will not properly verify authentication before accepting requests. This allows an attacker to add or remove information in the database concerning the audited systems, obtain or modify system configurations like SMTP or LDAP server addresses etc. Also, the 'backup' folder has user a password protection, but the password is hardcoded in the 'backup.php' script. The 'search.php' script is vulnerable to SQL injection, Cross-Site Scripting and Local File Include.