Description - Multiple Vulnerabilities in VNews

Multiple Vulnerabilities found in VNews script.

Exploit
Available
Solution
Not available - check vendor's website

1. SQL Injection.

Vulnerable scripts:
admin/admin.php
news.php

Parameters loginvar(admin/admin.php), news(news.php), nom(news.php) are not properly sanitized before being used in SQL queries. This can be used to evaluate arbitrary SQL expression(admin/admin.php) or make any SQL query by injecting arbitrary SQL code(news.php).

Condition: magic_quotes_gpc = off


2. Multiple Cross-Site Scripting.

Vulnerable Script: news.php

Parameters autorkomentarza, tresckomentarza are not properly sanitized. This can be used to post arbitrary HTML or web script code.


3. PHP Code Insertion.

Administrator has an ability to edit variable values from admin/config.php file. This can be used to insert arbitrary PHP code into config file which executes by every php-script.

System access is possible.

Condition: magic_quotes_gpc = off

Order PHP Code Testing

Protect against hacker attacks by source code analysis of your website or web application made by our team.The task will be done by experts in web application security.