MySource Multiple Vulnerabilities
BID:20153
Info
MySource Multiple Vulnerabilities
| Bugtraq ID: | 20153 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2006 12:00AM |
| Updated: | Sep 25 2006 10:21PM |
| Credit: | Patrick Webster is credited with the discovery of this vulnerability. |
| Vulnerable: |
Squiz MySource Matrix 3.8 Squiz MySource Matrix 3.7 Squiz MySource 2.16 Squiz MySource 2.14.8 |
| Not Vulnerable: | |
Discussion
MySource Multiple Vulnerabilities
MySource products are prone to multiple input-validation vulnerabilities. Exploiting these issues will allow an attacker to manipulate the application into becoming an HTTP proxy and to conduct cross-site scripting attacks.
An attacker may leverage these issues to cause the application to consume excessive bandwidth and to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These versions are vulnerable:
- MySource Matrix 3.8 and earlier
- MySource 2.x.
MySource products are prone to multiple input-validation vulnerabilities. Exploiting these issues will allow an attacker to manipulate the application into becoming an HTTP proxy and to conduct cross-site scripting attacks.
An attacker may leverage these issues to cause the application to consume excessive bandwidth and to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These versions are vulnerable:
- MySource Matrix 3.8 and earlier
- MySource 2.x.
Exploit / POC
MySource Multiple Vulnerabilities
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com.au/$page?sq_remote_page_action=fetch_url&sq_remote_page_url=http://www.example.com
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com.au/$page?sq_remote_page_action=fetch_url&sq_remote_page_url=http://www.example.com
Solution / Fix
MySource Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
MySource Multiple Vulnerabilities
References:
References:
- aushack.com advisory (Aushack)
- Squiz - My Source and My Source Matrix (Squiz)
- Squiz MySource Matrix Unauthorised Proxy and Cross Site Scripting ("Patrick Webster"
)