Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801153
Category:Web application abuses
Title:Xoops Celepar <= 2.2.4 Multiple Vulnerabilities - Active Check
Summary:Xoops Celepar is prone to multiple vulnerabilities.
Description:Summary:
Xoops Celepar is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- The flaw exists in 'Qas (aka Quas) module'. Input passed to the 'codigo' parameter in
modules/qas/aviso.php and modules/qas/imprimir.php, and the 'cod_categoria' parameter in
modules/qas/categoria.php is not properly sanitised before being used in an SQL query.

- The flaw exists in 'Qas (aka Quas) module' and 'quiz'module. Input passed to the 'opcao'
parameter to modules/qas/index.php, and via the URL to modules/qas/categoria.php,
modules/qas/index.php, and modules/quiz/cadastro_usuario.php is not properly sanitised before
being returned to the user.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute
arbitrary SQL statements on the vulnerable system, which may allow an attacker to view, add,
modify data, or delete information in the back-end database and also conduct cross-site
scripting.

Affected Software/OS:
Xoops Celepar version 2.2.4 and prior.

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-4698
BugTraq ID: 35820
http://www.securityfocus.com/bid/35820
http://www.exploit-db.com/exploits/9249
http://www.exploit-db.com/exploits/9261
http://osvdb.org/56593
http://www.osvdb.org/56594
http://osvdb.org/56595
http://secunia.com/advisories/35966
XForce ISS Database: celepar-aviso-sql-injection(51985)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51985
Common Vulnerability Exposure (CVE) ID: CVE-2009-4713
http://osvdb.org/56596
http://osvdb.org/56597
Common Vulnerability Exposure (CVE) ID: CVE-2009-4714
http://packetstormsecurity.org/0907-exploits/xoopsceleparquiz-xss.txt
http://www.osvdb.org/56598
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.