BigACE Cross Site Request Forgery and HTML Injection Vulnerabilities
BID:40354
Info
BigACE Cross Site Request Forgery and HTML Injection Vulnerabilities
| Bugtraq ID: | 40354 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2010 12:00AM |
| Updated: | May 25 2010 12:00AM |
| Credit: | Bkis |
| Vulnerable: |
BigACE BigACE 2.7.1 BigACE BigACE 1.8.2 BigACE BigACE 2.7 BigACE BigACE 2.6 BigACE BigACE 2.5 BigACE BigACE 2.4 |
| Not Vulnerable: |
BigACE BigACE 2.7.2 |
Discussion
BigACE Cross Site Request Forgery and HTML Injection Vulnerabilities
BigACE is prone to cross-site request-forgery and HTML-injection vulnerabilities.
Exploiting these issues can allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to BigACE 2.7.2 are vulnerable.
BigACE is prone to cross-site request-forgery and HTML-injection vulnerabilities.
Exploiting these issues can allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to BigACE 2.7.2 are vulnerable.
Exploit / POC
BigACE Cross Site Request Forgery and HTML Injection Vulnerabilities
An attacker can exploit HTML-injection issues through a browser. To exploit cross-site request-forgery issues, the attacker must entice an unsuspecting victim into visiting a malicious site.
An attacker can exploit HTML-injection issues through a browser. To exploit cross-site request-forgery issues, the attacker must entice an unsuspecting victim into visiting a malicious site.
Solution / Fix
BigACE Cross Site Request Forgery and HTML Injection Vulnerabilities
Solution:
Updates are available; please see the references for more information.
BigACE BigACE 2.7
BigACE BigACE 2.6
BigACE BigACE 2.4
BigACE BigACE 2.5
BigACE BigACE 1.8.2
BigACE BigACE 2.7.1
Solution:
Updates are available; please see the references for more information.
BigACE BigACE 2.7
-
BigACE bigace_2.7.2.zip
http://sourceforge.net/projects/bigace/files/1_BIGACE%20CMS/bigace_2.7 .2.zip/download
BigACE BigACE 2.6
-
BigACE bigace_2.7.2.zip
http://sourceforge.net/projects/bigace/files/1_BIGACE%20CMS/bigace_2.7 .2.zip/download
BigACE BigACE 2.4
-
BigACE bigace_2.7.2.zip
http://sourceforge.net/projects/bigace/files/1_BIGACE%20CMS/bigace_2.7 .2.zip/download
BigACE BigACE 2.5
-
BigACE bigace_2.7.2.zip
http://sourceforge.net/projects/bigace/files/1_BIGACE%20CMS/bigace_2.7 .2.zip/download
BigACE BigACE 1.8.2
-
BigACE bigace_2.7.2.zip
http://sourceforge.net/projects/bigace/files/1_BIGACE%20CMS/bigace_2.7 .2.zip/download
BigACE BigACE 2.7.1
-
BigACE bigace_2.7.2.zip
http://sourceforge.net/projects/bigace/files/1_BIGACE%20CMS/bigace_2.7 .2.zip/download
References
BigACE Cross Site Request Forgery and HTML Injection Vulnerabilities
References:
References:
- Admin Error: 403 Forbidden (jmokie)
- BIGACE 2.7.2 (BigACE)
- BigACE Homepage (BigACE)
- [Bkis-01-2010] Multiple Vulnerabilities in BigAce - Bkis ("Bkis"
)