Magnolia CE 'ActivationHandler' URL Security Bypass Vulnerability
BID:27608
Info
Magnolia CE 'ActivationHandler' URL Security Bypass Vulnerability
| Bugtraq ID: | 27608 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0701 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Philipp Bracher is credited with the discovery of this vulnerability. |
| Vulnerable: |
Magnolia Magnolia CE 3.5.3 Magnolia Magnolia CE 3.5.2 Magnolia Magnolia CE 3.5.1 Magnolia Magnolia CE 3.5 |
| Not Vulnerable: |
Magnolia Magnolia CE 3.5.4 |
Discussion
Magnolia CE 'ActivationHandler' URL Security Bypass Vulnerability
Magnolia CE is prone to a security-bypass vulnerability because it fails to check permissions on certain pages.
An unauthorized attacker can exploit this issue to add arbitrary content to the site running the affected application. This may lead to other attacks.
This issue affects versions prior to Magnolia CE 3.5.4.
Magnolia CE is prone to a security-bypass vulnerability because it fails to check permissions on certain pages.
An unauthorized attacker can exploit this issue to add arbitrary content to the site running the affected application. This may lead to other attacks.
This issue affects versions prior to Magnolia CE 3.5.4.
Exploit / POC
Magnolia CE 'ActivationHandler' URL Security Bypass Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Magnolia CE 'ActivationHandler' URL Security Bypass Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Magnolia Magnolia CE 3.5
Magnolia Magnolia CE 3.5.1
Magnolia Magnolia CE 3.5.2
Magnolia Magnolia CE 3.5.3
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Magnolia Magnolia CE 3.5
-
Magnolia magnolia-tomcat-bundle-3.5.4-bundle-jdk14.tar.gz
http://downloads.sourceforge.net/magnolia/magnolia-tomcat-bundle-3.5.4 -bundle-jdk14.tar.gz?modtime=1201870459&big_mirror=1
Magnolia Magnolia CE 3.5.1
-
Magnolia magnolia-tomcat-bundle-3.5.4-bundle-jdk14.tar.gz
http://downloads.sourceforge.net/magnolia/magnolia-tomcat-bundle-3.5.4 -bundle-jdk14.tar.gz?modtime=1201870459&big_mirror=1
Magnolia Magnolia CE 3.5.2
-
Magnolia magnolia-tomcat-bundle-3.5.4-bundle-jdk14.tar.gz
http://downloads.sourceforge.net/magnolia/magnolia-tomcat-bundle-3.5.4 -bundle-jdk14.tar.gz?modtime=1201870459&big_mirror=1
Magnolia Magnolia CE 3.5.3
-
Magnolia magnolia-tomcat-bundle-3.5.4-bundle-jdk14.tar.gz
http://downloads.sourceforge.net/magnolia/magnolia-tomcat-bundle-3.5.4 -bundle-jdk14.tar.gz?modtime=1201870459&big_mirror=1
References
Magnolia CE 'ActivationHandler' URL Security Bypass Vulnerability
References:
References:
- activation: security hole if you activate a new item (Magnolia)
- Magnolia CE Homepage (Magnolia)