[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

DotProject 2.1.5 SQL Injection / Cross Site Scripting

Author
Canberk BOLAT
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-19601
Category
web applications
Date add
21-10-2012
Platform
php
Information
--------------------
Name :  XSS and SQL Injection Vulnerabilities in DotProject
Software :  DotProject 2.1.5 and possibly below.
Vendor Homepage :  http://www.dotproject.net
Vulnerability Type :  Cross-Site Scripting and SQL Injection
Severity :  Critical
Researcher :  Canberk Bolat
Advisory Reference :  NS-12-014

Description
--------------------
dotProject is a volunteer supported Project Management application.
There is no "company" behind this project, it is managed, maintained,
developed and supported by a volunteer group and by the users
themselves.

Details
--------------------
DotProject is affected by XSS and SQL Injection vulnerabilities in
version 2.1.5.

You can read the full article about Cross-Site Scripting and SQL
Injection vulnerabilities from here :

Cross-site Scripting (XSS)
SQL Injection
Solution
--------------------
Upgrade to the latest dotProject version (2.1.6 or later).

Advisory Timeline
--------------------
05/12/2011 - First Contact
31/12/2011 - Second Contact
14/08/2012 - Vulnerability fixed in dotProject 2.1.6
19/10/2012 - Advisory Released

Credits
--------------------
It has been discovered on testing of Netsparker, Web Application
Security Scanner - http://www.mavitunasecurity.com/netsparker/.

References
--------------------
Vendor Url / Patch : -
MSL Advisory Link :
http://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-dotproject/
Netsparker Advisories : http://www.mavitunasecurity.com/netsparker-advisories/

#  0day.today [2024-11-15]  #