vendor:
SiteBar
by:
Unknown
7.5
CVSS
HIGH
Input-Validation
79
CWE
Product Name: SiteBar
Affected Version From: 3.3.2008
Affected Version To: 3.3.2008
Patch Exists: YES
Related CWE: CVE-2007-6054, CVE-2007-6055, CVE-2007-6056, CVE-2007-6057
CPE: a:sitebar:sitebar:3.3.8
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-0436/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-0436/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-0673/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-0672/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-0673/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-0672/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-0014/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-0014/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2007-0014/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2007-0014/
Platforms Tested:
2007
Multiple Input-Validation Vulnerabilities in SiteBar
SiteBar is prone to multiple input-validation vulnerabilities because it fails to properly sanitize user-supplied input. These issues include: - A local file-include vulnerability - Multiple arbitrary-script-code-execution vulnerabilities - Multiple cross-site scripting vulnerabilities - A URI-redirection vulnerability. Exploiting these issues can allow attackers to access potentially sensitive information, to execute arbitrary script code in the context of the webserver process, to steal cookie-based authentication credentials, and to redirect users to malicious webpages.
Mitigation:
To mitigate these vulnerabilities, it is recommended to update to the latest version of SiteBar (version 3.3.9 or later). Additionally, input validation should be implemented to properly sanitize user-supplied input.