TYPO3 WT Gallery Extension Multiple Input Validation Vulnerabilities
BID:29182
Info
TYPO3 WT Gallery Extension Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 29182 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6630 CVE-2008-2526 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Helmut Hummel and Henning Pingel from the Typo3 security team |
| Vulnerable: |
Alexander Kellner WT Gallery 2.6.2 Alexander Kellner WT Gallery 2.5 |
| Not Vulnerable: |
Alexander Kellner WT Gallery 2.6.3 |
Discussion
TYPO3 WT Gallery Extension Multiple Input Validation Vulnerabilities
The WT Gallery extension for TYPO3 is prone to a cross-site scripting vulnerability and multiple information-disclosure vulnerabilities because it fails to properly verify user-supplied input.
An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
WT Gallery (wt_gallery) 2.6.2 and earlier are affected by the cross-site scripting issue.
WT Gallery (wt_gallery) 2.5.0 and earlier are affected by the information-disclosure issues.
The WT Gallery extension for TYPO3 is prone to a cross-site scripting vulnerability and multiple information-disclosure vulnerabilities because it fails to properly verify user-supplied input.
An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
WT Gallery (wt_gallery) 2.6.2 and earlier are affected by the cross-site scripting issue.
WT Gallery (wt_gallery) 2.5.0 and earlier are affected by the information-disclosure issues.
Exploit / POC
TYPO3 WT Gallery Extension Multiple Input Validation Vulnerabilities
Attackers can exploit these issues with a browser. To exploit the cross-site scripting vulnerability, an attacker must entice an unsuspecting victim into following a malicious URI.
Attackers can exploit these issues with a browser. To exploit the cross-site scripting vulnerability, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
TYPO3 WT Gallery Extension Multiple Input Validation Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Alexander Kellner WT Gallery 2.5
Alexander Kellner WT Gallery 2.6.2
Solution:
The vendor has released an update. Please see the references for more information.
Alexander Kellner WT Gallery 2.5
-
Alexander Kellner wt_gallery_2.6.3.t3x
http://typo3.org/fileadmin/ter/w/t/wt_gallery_2.6.3.t3x
Alexander Kellner WT Gallery 2.6.2
-
Alexander Kellner wt_gallery_2.6.3.t3x
http://typo3.org/fileadmin/ter/w/t/wt_gallery_2.6.3.t3x
References
TYPO3 WT Gallery Extension Multiple Input Validation Vulnerabilities
References:
References:
- Synnefoims Homepage (synnefoims)
- http://typo3.org/teams/security/security-bulletins/typo3-20080513-1/ (Typo3)