ASP Stats Generator settings_skin.asp ASP code execution

aspstatsgenerator-settingskin-code-execution (27284) The risk level is classified as MediumMedium Risk

Description:

ASP Stats Generator could allow a remote attacker with valid authentication credentials to inject and execute arbitrary ASP code on the system. An attacker could send a specially-crafted URL request to the skin.asp script using the strAsgSknPageBgColour parameter to inject and execute arbitrary ASP code on the system.


Consequences:

Data Manipulation

Remedy:

Upgrade to the latest version of ASP Stats Generator (2.1.2 or later), available from the ASP Stats Generator Web site. See References.

References:

  • ASP Stats Generator Web site: ASP Stats Generator.
  • CVE-2006-3184: Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.
  • SA20721: ASP Stats Generator SQL Injection and Code Injection
  • VUPEN/ADV-2006-2414: ASP Stats Generator Remote SQL Injection and Code Execution Vulnerabilities

Platforms Affected:

  • ASP Stats Generator ASP Stats Generator 2.1.1

Reported:

Jun 19, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page