PT-2007-1019 · Sitebar · Sitebar

Tim Brown

·

Published

2007-10-17

·

Updated

2018-10-15

·

CVE-2007-5692

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SiteBar version 3.3.8
Description: The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be achieved through various parameters, including the lang parameter to "integrator.php", the token parameter in a New Password action, the nid acl parameter in a Folder Properties action, the uid parameter in a Modify User action to "command.php", or the target parameter to "index.php". The exploitation can be carried out by a remote attacker who has passed the authentication procedure.
Recommendations: For SiteBar version 3.3.8, consider disabling access to the vulnerable parameters, such as lang, token, nid acl, uid, and target, until a patch is available. Restrict access to the affected scripts, including "integrator.php", "command.php", and "index.php", to minimize the risk of exploitation. Avoid using these parameters in the respective actions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02683
CVE-2007-5692
DSA-1423-1

Affected Products

Sitebar