Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection Vulnerability
BID:27550
Info
Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection Vulnerability
| Bugtraq ID: | 27550 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0179 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2008 12:00AM |
| Updated: | Jan 31 2008 10:57PM |
| Credit: | Tomasz Kuczynski is credited with the discovery of this vulnerability. |
| Vulnerable: |
Liferay Enterprise Portal 4.3.6 Liferay Enterprise Portal 4.3.1 Liferay Enterprise Portal 4.1.3 Liferay Enterprise Portal 4.1.1 Liferay Enterprise Portal 4.1 Liferay Enterprise Portal 3.6.1 Liferay Enterprise Portal 2.2 .0 Liferay Enterprise Portal 2.1.1 Liferay Enterprise Portal 2.1 .0 Liferay Enterprise Portal 2.0 .x Liferay Enterprise Portal 1.x Liferay Enterprise Portal |
| Not Vulnerable: |
Liferay Enterprise Portal 4.4 Liferay Enterprise Portal 4.3.7 |
Discussion
Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection Vulnerability
Liferay Enterprise Portal is prone to a script-code-injection vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to inject arbitrary script code into 'Forgot Password' emails sent by the affected application. This may help the attacker obtain potentially sensitive information that can aid in other attacks.
Versions prior to Liferay Enterprise Portal 4.4.0 and 4.3.7 are vulnerable.
Liferay Enterprise Portal is prone to a script-code-injection vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to inject arbitrary script code into 'Forgot Password' emails sent by the affected application. This may help the attacker obtain potentially sensitive information that can aid in other attacks.
Versions prior to Liferay Enterprise Portal 4.4.0 and 4.3.7 are vulnerable.
Exploit / POC
Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection Vulnerability
An attacker can exploit this issue using a browser.
An attacker can exploit this issue using a browser.
Solution / Fix
Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection Vulnerability
Solution:
The vendor released fixes and an advisory to address this issue. Please see the references for more information.
Liferay Enterprise Portal 4.3.6
Solution:
The vendor released fixes and an advisory to address this issue. Please see the references for more information.
Liferay Enterprise Portal 4.3.6
-
Liferay liferay-portal-src-4.4.0.zip
http://downloads.sourceforge.net/lportal/liferay-portal-src-4.4.0.zip? modtime=1201282487&big_mirror=1
References
Liferay Enterprise Portal 'User-Agent' HTTP Header Script Injection Vulnerability
References:
References:
- Liferay Homepage (Liferay)
- Forgot password XSS vulnerability (Lifreay)
- VU#888209 Liferay Portal Forgot Password User-Agent HTTP header XSS (US-CERT)