Liferay Enterprise Portal Multiple XSS Vulnerabilities
BID:10402
Info
Liferay Enterprise Portal Multiple XSS Vulnerabilities
| Bugtraq ID: | 10402 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2004 12:00AM |
| Updated: | May 22 2004 12:00AM |
| Credit: | Discovered by Sandeep Giri. |
| Vulnerable: |
Liferay Enterprise Portal 5.1.2 Liferay Enterprise Portal 2.1.1 Liferay Enterprise Portal 2.1 .0 Liferay Enterprise Portal 2.0 .x Liferay Enterprise Portal 1.x |
| Not Vulnerable: |
Liferay Enterprise Portal 2.2 .0 |
Discussion
Liferay Enterprise Portal Multiple XSS Vulnerabilities
It has been reported that Liferay Enterprise Portal is susceptible to multiple cross-site scripting and HTML injection vulnerabilities. User-supplied data from many input fields is included in server generated content without appropriate validation/encoding. This may allow for typical cross-site scripting attacks against other users of the portal.
It has been reported that Liferay Enterprise Portal is susceptible to multiple cross-site scripting and HTML injection vulnerabilities. User-supplied data from many input fields is included in server generated content without appropriate validation/encoding. This may allow for typical cross-site scripting attacks against other users of the portal.
Exploit / POC
Liferay Enterprise Portal Multiple XSS Vulnerabilities
There is no exploit code possible. The following example was provided:
Test:
Add a message with subject <script>history.go(-1)</script>
Now, no user can see message board.
There is no exploit code possible. The following example was provided:
Test:
Add a message with subject <script>history.go(-1)</script>
Now, no user can see message board.
Solution / Fix
Liferay Enterprise Portal Multiple XSS Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Liferay Enterprise Portal 1.x
Liferay Enterprise Portal 2.0 .x
Liferay Enterprise Portal 2.1 .0
Liferay Enterprise Portal 2.1.1
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Liferay Enterprise Portal 1.x
-
Liferay liferay-ep-2.2.0-src.zip
http://prdownloads.sourceforge.net/lportal/liferay-ep-2.2.0-src.zip?do wnload
Liferay Enterprise Portal 2.0 .x
-
Liferay liferay-ep-2.2.0-src.zip
http://prdownloads.sourceforge.net/lportal/liferay-ep-2.2.0-src.zip?do wnload
Liferay Enterprise Portal 2.1 .0
-
Liferay liferay-ep-2.2.0-src.zip
http://prdownloads.sourceforge.net/lportal/liferay-ep-2.2.0-src.zip?do wnload
Liferay Enterprise Portal 2.1.1
-
Liferay liferay-ep-2.2.0-src.zip
http://prdownloads.sourceforge.net/lportal/liferay-ep-2.2.0-src.zip?do wnload
References
Liferay Enterprise Portal Multiple XSS Vulnerabilities
References:
References:
- Liferay Homepage (Liferay)
- Release Name: 2.2.0 (Liferay)
- Liferay Cross Site Scripting Flaw ("Giri, Sandeep"
) - Re: Liferay Cross Site Scripting Flaw (michael young
)