Pentaho BI Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
BID:36672
Info
Pentaho BI Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
| Bugtraq ID: | 36672 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 14 2009 12:00AM |
| Updated: | Oct 16 2009 07:28PM |
| Credit: | Michele "euronymous" Orru' |
| Vulnerable: |
Pentaho BI 1.7 .1062 Pentaho BI 1.2 RC3 Pentaho BI 1.2 RC2 |
| Not Vulnerable: | |
Discussion
Pentaho BI Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
Pentaho BI is prone to multiple cross-site scripting and information-disclosure vulnerabilities because it fails to properly validate user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. The attacker may also exploit these issues to obtain sensitive session information.
Pentaho BI 1.7.0.1062 is vulnerable; other versions may also be affected.
Pentaho BI is prone to multiple cross-site scripting and information-disclosure vulnerabilities because it fails to properly validate user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. The attacker may also exploit these issues to obtain sensitive session information.
Pentaho BI 1.7.0.1062 is vulnerable; other versions may also be affected.
Exploit / POC
Pentaho BI Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
Attackers may exploit these issues via a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example data is available:
Attackers may exploit these issues via a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example data is available:
Solution / Fix
Pentaho BI Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Pentaho BI Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
References:
References:
- Pentaho Homepage (Pentaho)
- [AntiSnatchOr] Pentaho Bi-server multiple vulnerabilities (Michele Orru
)