Liferay Enterprise Portal 'exportFileName' File Creation Remote Code Execution Vulnerability
BID:42429
Info
Liferay Enterprise Portal 'exportFileName' File Creation Remote Code Execution Vulnerability
| Bugtraq ID: | 42429 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2010 12:00AM |
| Updated: | Aug 13 2010 06:34PM |
| Credit: | Stefano Di Paola of Minded Security |
| Vulnerable: |
Liferay Enterprise Portal 4.4.2 |
| Not Vulnerable: |
Liferay Enterprise Portal 6.0.4 GA |
Discussion
Liferay Enterprise Portal 'exportFileName' File Creation Remote Code Execution Vulnerability
Liferay Enterprise Portal is prone to a remote code-execution vulnerability because it allows users to save arbitrary content to an arbitrary 'jsp' file on the affected computer.
Successfully exploiting this issue will allow attackers to execute arbitrary script code in the context of the webserver.
Liferay Enterprise Portal 4.4.2 is vulnerable; other versions may also be affected.
Liferay Enterprise Portal is prone to a remote code-execution vulnerability because it allows users to save arbitrary content to an arbitrary 'jsp' file on the affected computer.
Successfully exploiting this issue will allow attackers to execute arbitrary script code in the context of the webserver.
Liferay Enterprise Portal 4.4.2 is vulnerable; other versions may also be affected.
Exploit / POC
Liferay Enterprise Portal 'exportFileName' File Creation Remote Code Execution Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Liferay Enterprise Portal 'exportFileName' File Creation Remote Code Execution Vulnerability
Solution:
The vendor has released a fix to resolve this issue; please see the references for more information.
Solution:
The vendor has released a fix to resolve this issue; please see the references for more information.
References
Liferay Enterprise Portal 'exportFileName' File Creation Remote Code Execution Vulnerability
References:
References:
- Home page (Liferay)
- Path manipulation may lead to remote code execution (Liferay)