vendor:
phpRS
by:
Not specified
7.5
CVSS
HIGH
SQL Injection, Cross-Site Scripting
89, 79
CWE
Product Name: phpRS
Affected Version From: 2.8.2001
Affected Version To: 2.8.2001
Patch Exists: NO
Related CWE: CVE-2011-2018, CVE-2011-2019
CPE: a:phpRS:phpRS:2.8.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/mfsa2019-02-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/mfsa2019-01-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-18505/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2011-2767/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2011-2767/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-2767/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2011-2767/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2022-31631/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2011-5327/
Platforms Tested:
2011
phpRS Multiple SQL Injection and Cross-Site Scripting Vulnerabilities
The phpRS application is prone to multiple SQL-injection vulnerabilities and multiple cross-site scripting vulnerabilities. These vulnerabilities occur due to insufficient sanitization of user-supplied data. Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Mitigation:
To mitigate these vulnerabilities, it is recommended to sanitize and validate user-supplied input before using it in SQL queries or displaying it in web pages. Additionally, keeping the phpRS application up-to-date with the latest security patches and versions is advised.