Liferay Enterprise Portal User Profile Greeting HTML Injection Vulnerability
BID:27546
Info
Liferay Enterprise Portal User Profile Greeting HTML Injection Vulnerability
| Bugtraq ID: | 27546 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0180 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2008 12:00AM |
| Updated: | Jan 31 2008 10:07PM |
| Credit: | Tomasz Kuczynski is credited with the discovery of this vulnerability. |
| Vulnerable: |
Liferay Enterprise Portal 5.1.2 Liferay Enterprise Portal 4.3.1 Liferay Enterprise Portal 4.1.3 Liferay Enterprise Portal 4.1.1 Liferay Enterprise Portal 4.1 Liferay Enterprise Portal 3.6.1 Liferay Enterprise Portal 2.2 .0 Liferay Enterprise Portal 2.1.1 Liferay Enterprise Portal 2.1 .0 Liferay Enterprise Portal 2.0 .x Liferay Enterprise Portal 1.x Liferay Enterprise Portal |
| Not Vulnerable: |
Liferay Enterprise Portal 4.4 Liferay Enterprise Portal 4.3.7 |
Discussion
Liferay Enterprise Portal User Profile Greeting HTML Injection Vulnerability
Liferay Enterprise Portal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects versions prior to Liferay Enterprise Portal 4.4.0 and 4.3.7.
Liferay Enterprise Portal is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
This issue affects versions prior to Liferay Enterprise Portal 4.4.0 and 4.3.7.
Exploit / POC
Liferay Enterprise Portal User Profile Greeting HTML Injection Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Liferay Enterprise Portal User Profile Greeting HTML Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Liferay Enterprise Portal User Profile Greeting HTML Injection Vulnerability
References:
References:
- Greeting exposes XSS vulnerability (Brian Chan)
- Vulnerability Note VU#732449 (US-CERT)