pyForum Cross Site Request Forgery and HTML Injection Vulnerabilities
BID:41738
Info
pyForum Cross Site Request Forgery and HTML Injection Vulnerabilities
| Bugtraq ID: | 41738 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2009 12:00AM |
| Updated: | Dec 15 2009 12:00AM |
| Credit: | Hoang Quoc Thinh and Blue Moon Consulting |
| Vulnerable: |
Pyforum Pyforum 1.0.3 |
| Not Vulnerable: | |
Discussion
pyForum Cross Site Request Forgery and HTML Injection Vulnerabilities
pyForum is prone to a cross-site request-forgery vulnerability and multiple HTML-injection vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
pyForum version 1.0.3 is vulnerable; other versions may also be affected.
pyForum is prone to a cross-site request-forgery vulnerability and multiple HTML-injection vulnerabilities.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, delete certain data, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
pyForum version 1.0.3 is vulnerable; other versions may also be affected.
Exploit / POC
pyForum Cross Site Request Forgery and HTML Injection Vulnerabilities
An attacker can exploit HTML-injection issues through a browser. To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting user into visiting a malicious site.
An attacker can exploit HTML-injection issues through a browser. To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting user into visiting a malicious site.
Solution / Fix
pyForum Cross Site Request Forgery and HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
pyForum Cross Site Request Forgery and HTML Injection Vulnerabilities
References:
References:
- pyForum Homepage (pyForum)