e107 'CAPTCHA' Security Bypass Vulnerability and Multiple Cross Site Scripting Vulnerabilities
BID:36532
Info
e107 'CAPTCHA' Security Bypass Vulnerability and Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 36532 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2009 12:00AM |
| Updated: | Sep 28 2009 10:20PM |
| Credit: | MustLive |
| Vulnerable: |
e107 e107 0.7.16 e107 e107 0.7.15 e107 e107 0.7.13 e107 e107 0.7.8 e107 e107 0.7.5 |
| Not Vulnerable: | |
Discussion
e107 'CAPTCHA' Security Bypass Vulnerability and Multiple Cross Site Scripting Vulnerabilities
e107 is prone to a security-bypass vulnerability and multiple cross-site scripting vulnerabilities.
Successfully exploiting the security-bypass issue will allow an attacker to bypass the 'CAPTCHA' security mechanism. This may lead to other attacks.
The attacker could exploit the cross-site scripting issues to execute arbitrary script code in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
e107 is prone to a security-bypass vulnerability and multiple cross-site scripting vulnerabilities.
Successfully exploiting the security-bypass issue will allow an attacker to bypass the 'CAPTCHA' security mechanism. This may lead to other attacks.
The attacker could exploit the cross-site scripting issues to execute arbitrary script code in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
e107 'CAPTCHA' Security Bypass Vulnerability and Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit the security bypass issue by using readily available tools. To exploit the cross-site scripting vulnerabilities, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following proof-of-concept URIs are available:
Attackers can exploit the security bypass issue by using readily available tools. To exploit the cross-site scripting vulnerabilities, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following proof-of-concept URIs are available:
Solution / Fix
e107 'CAPTCHA' Security Bypass Vulnerability and Multiple Cross Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
e107 'CAPTCHA' Security Bypass Vulnerability and Multiple Cross Site Scripting Vulnerabilities
References:
References:
- e107 Inc. announces new branding and the release of v1.0 (e107)
- Vulnerabilities in E107 ("MustLive"
)