Portili Personal and Team Wiki Multiple Security Vulnerabilities
BID:41973
Info
Portili Personal and Team Wiki Multiple Security Vulnerabilities
| Bugtraq ID: | 41973 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2009 12:00AM |
| Updated: | Nov 04 2009 12:00AM |
| Credit: | Abysssec Security Researches |
| Vulnerable: |
Portili Team Wiki 1.14 Portili Personal Wiki 1.14 |
| Not Vulnerable: | |
Discussion
Portili Personal and Team Wiki Multiple Security Vulnerabilities
Portili Personal and Team Wiki are prone to multiple security vulnerabilities. These vulnerabilities include a cross-site scripting vulnerability, an arbitrary-file-upload vulnerability, and multiple information-disclosure vulnerabilities.
Attackers can exploit these issues to obtain sensitive information, steal cookie-based authentication information, upload arbitrary files to the affected computer, and execute arbitrary script code in the context of the browser.
Personal Wiki 1.14 and Team Wiki 1.14 are vulnerable; other versions may also be affected.
Portili Personal and Team Wiki are prone to multiple security vulnerabilities. These vulnerabilities include a cross-site scripting vulnerability, an arbitrary-file-upload vulnerability, and multiple information-disclosure vulnerabilities.
Attackers can exploit these issues to obtain sensitive information, steal cookie-based authentication information, upload arbitrary files to the affected computer, and execute arbitrary script code in the context of the browser.
Personal Wiki 1.14 and Team Wiki 1.14 are vulnerable; other versions may also be affected.
Exploit / POC
Portili Personal and Team Wiki Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
Attackers can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URI is available:
Solution / Fix
Portili Personal and Team Wiki Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Portili Personal and Team Wiki Multiple Security Vulnerabilities
References:
References:
- Portili Homepage (Portili)
- Portili Wiki Change Logs (Portili)