Contact Us
SECURITY BLOG SECURITY DASHBOARD PARTNERS PRODUCTS JOBS SERVICES COMPANY HOME
Network Security Consulting Advisories Article

RETIRED: Zoph Multiple Remote Security Vulnerabilities

http://www.securityfocus.com/bid/53788

Security Info

Bugtraq ID: 53788
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Jun 05 2012 12:00AM
Updated: Jun 25 2012 09:30PM
Credit: KedAns-Dz
Vulnerable: Zoph Zoph 0.9pre2
Not Vulnerable:

Security Discussion

Zoph is prone to multiple remote security vulnerabilities, which include:

1. An arbitrary download vulnerability.
2. An SQL-injection vulnerability.
3. A cross-site request-forgery vulnerability.

Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database and gain access to sensitive information. Other attacks are also possible.

Zoph 0.9pre2 is vulnerable; other versions may also be affected.

Note: This BID is being retired. The issue can not be exploited as described.

Proof of Concept and Security Exploits

Attackers can use a browser to exploit these issues.

The following example inputs are available:

Security Solution(s)

Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.

Security References(s)

References:

Contact Us

Security Penetration Testing

Security Questions

Security Dashboard

Emagined Security Blog featuring Dr. Eugene Schultz
Site Updated June 19, 2013
©2000-2013 Emagined Security
All Rights Reserved

Secure Web Programming
by Vizual Services