Woltlab Burning Board Multiple Input Validation Vulnerabilites
BID:34057
Info
Woltlab Burning Board Multiple Input Validation Vulnerabilites
| Bugtraq ID: | 34057 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2009 12:00AM |
| Updated: | Mar 12 2009 03:26PM |
| Credit: | Juri Gianni aka yeat |
| Vulnerable: |
Woltlab Burning Board 3.0.5 Woltlab Burning Board 3.0.3 PL 1 Woltlab Burning Board 3.0 |
| Not Vulnerable: | |
Discussion
Woltlab Burning Board Multiple Input Validation Vulnerabilites
Woltlab Burning Board is prone to multiple input-validation vulnerabilities:
- Multiple security issues may allow attackers to delete private messages
- A cross-site scripting issue
- Multiple URI-redirection issues
Attackers can exploit these issues to delete private messages, execute arbitrary script code, steal cookie-based authentication credentials, and redirect users to malicious sites.
Woltlab Burning Board is prone to multiple input-validation vulnerabilities:
- Multiple security issues may allow attackers to delete private messages
- A cross-site scripting issue
- Multiple URI-redirection issues
Attackers can exploit these issues to delete private messages, execute arbitrary script code, steal cookie-based authentication credentials, and redirect users to malicious sites.
Exploit / POC
Woltlab Burning Board Multiple Input Validation Vulnerabilites
The attacker can exploit these issues through a browser. To exploit the cross-site scripting and URI-redirection vulnerabilities, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/[path]/wcf/acp/dereferrer.php?url=javascript:alert("Example");
http://www.example.com/[path]/wcf/acp/dereferrer.php?url=http://[host]
http://www.example.com/[path]/wbb/?page=ThreadAction&action=deleteAll&boardID=1&url=[local URL]
The attacker can exploit these issues through a browser. To exploit the cross-site scripting and URI-redirection vulnerabilities, the attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/[path]/wcf/acp/dereferrer.php?url=javascript:alert("Example");
http://www.example.com/[path]/wcf/acp/dereferrer.php?url=http://[host]
http://www.example.com/[path]/wbb/?page=ThreadAction&action=deleteAll&boardID=1&url=[local URL]
Solution / Fix
Woltlab Burning Board Multiple Input Validation Vulnerabilites
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Woltlab Burning Board Multiple Input Validation Vulnerabilites
References:
References:
- Woltlab Burning Board Homepage (Woltlab)