Release date:
Updated on:
Affected Systems:
Laytontechnology HelpBox 4.4.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56298
Cve id: CVE-2012-4971, CVE-2012-4972, CVE-2012-4974, CVE-2012-4975, CVE-2012-4976
Layton Helpbox is a WEB-based desktop help system.
HelpBox 4.4.0 and other versions have multiple security vulnerabilities, attackers can exploit these vulnerabilities to access or modify data, exploit other vulnerabilities in the underlying database, bypass certain security restrictions, obtain administrator access permissions, execute HTML and script code, and steal Cookie authentication creden, controls the out-of-site light.
<* Source: Joseph Sheridan
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Laytontechnology
----------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.laytontechnology.com/