Open Blog Multiple Input Validation Vulnerabilities
BID:42597
Info
Open Blog Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 42597 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2010 12:00AM |
| Updated: | Aug 23 2010 12:00AM |
| Credit: | Duong Manh Linh, Truong Tu Hai, Nguyen Hoang Vinh - Bkis |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Open Blog Multiple Input Validation Vulnerabilities
Open Blog is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input; these vulnerabilities include an authentication-bypass vulnerability, multiple cross-site-scripting vulnerabilities, and multiple cross-site request-forgery vulnerabilities.
Attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, compromise the affected application, and modify administration settings, and gain administrative access to the affected application. Other attacks may be possible.
Tomaz Muraus Open Blog 1.2.1 is vulnerable; other versions may be affected.
Open Blog is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input; these vulnerabilities include an authentication-bypass vulnerability, multiple cross-site-scripting vulnerabilities, and multiple cross-site request-forgery vulnerabilities.
Attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, compromise the affected application, and modify administration settings, and gain administrative access to the affected application. Other attacks may be possible.
Tomaz Muraus Open Blog 1.2.1 is vulnerable; other versions may be affected.
Exploit / POC
Open Blog Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issue. For the cross-site scripting and cross-site request-forgery vulnerabilities, an attacker must trick a victim into following a malicious URI.
Attackers can use a browser to exploit these issue. For the cross-site scripting and cross-site request-forgery vulnerabilities, an attacker must trick a victim into following a malicious URI.
Solution / Fix
Open Blog Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Open Blog Multiple Input Validation Vulnerabilities
References:
References:
- [Bkis-04-2010] Multiple Vulnerabilities in OpenBlog Aug 23 2010 03:36AM (Bkis)
- Open Blog - Homepage (Tomaz Muraus)