vendor:
WebsiteBaker
by:
Manuel Garcia Cardenas
N/A
CVSS
N/A
SQL Injection, Cross-Site Scripting, HTTP Response Splitting
89, 79, 113
CWE
Product Name: WebsiteBaker
Affected Version From: 2.8.3
Affected Version To: 2.8.3
Patch Exists: YES
Related CWE: N/A
CPE: 2.8.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Multiple Vulnerabilities in WebsiteBaker 2.8.3
It is possible to inject SQL code in the variable 'id' on the page 'modify.php'. This bug was found using the portal without authentication. To exploit the vulnerability only is needed use the version 1.0 of the HTTP protocol to interact with the application. Has been detected a reflected XSS vulnerability in WebsiteBaker, that allows the execution of arbitrary HTML/script code to be executed in the context of the victim user's browser. An input validation problem exists within WebsiteBaker which allows injecting CR (carriage return - %0D or ) and LF (line feed - %0A or ) characters into the server HTTP response header, resulting in a HTTP Response Splitting Vulnerability.
Mitigation:
Upgrade to the latest version of WebsiteBaker.