Liferay Portal 'p_p_id' Parameter HTML Injection Vulnerability
BID:37615
Info
Liferay Portal 'p_p_id' Parameter HTML Injection Vulnerability
| Bugtraq ID: | 37615 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3742 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2010 12:00AM |
| Updated: | Jan 05 2010 12:00AM |
| Credit: | Tomasz Kuczynski |
| Vulnerable: |
Liferay Enterprise Portal 5.3 |
| Not Vulnerable: | |
Discussion
Liferay Portal 'p_p_id' Parameter HTML Injection Vulnerability
Liferay Portal is prone to a HTML-injection vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
Liferay Portal 5.3.0 is vulnerable; other versions may also be affected.
Liferay Portal is prone to a HTML-injection vulnerability because the application fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.
Liferay Portal 5.3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Liferay Portal 'p_p_id' Parameter HTML Injection Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Liferay Portal 'p_p_id' Parameter HTML Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Liferay Portal 'p_p_id' Parameter HTML Injection Vulnerability
References:
References:
- Liferay Homepage (Liferay)
- Malicious JavaScript can be inserted into the Plugins Configuration section of C (Liferay)
- Vulnerability Note VU#750796 (US-CERT)