phpCAS Proxy Mode Multiple Security Vulnerabilities
BID:43585
Info
phpCAS Proxy Mode Multiple Security Vulnerabilities
| Bugtraq ID: | 43585 |
| Class: | Unknown |
| CVE: |
CVE-2010-3690 CVE-2010-3691 CVE-2010-3692 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 25 2010 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Joachim Fritschi |
| Vulnerable: |
Moodle moodle 1.9.9 Moodle moodle 1.9.8 Moodle moodle 1.9.7 Moodle moodle 1.9.6 Moodle moodle 1.9.4 Moodle moodle 1.9.3 Moodle moodle 1.9.2 Moodle moodle 1.8.13 Moodle moodle 1.8.11 Moodle moodle 1.8.10 Moodle moodle 1.8.9 Moodle moodle 1.8.9 Moodle moodle 1.8.8 Moodle moodle 1.8.7 Moodle moodle 1.8.6 Moodle moodle 1.8.5 Moodle moodle 1.8.4 Moodle moodle 1.8.3 Moodle moodle 1.8.2 Jasig phpCAS 1.1.1 Jasig phpCAS 1.1 Jasig phpCAS 1.1.2 Jasig phpCAS 1.0.1 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Moodle moodle 1.9.10 Moodle moodle 1.8.14 Jasig phpCAS 1.2 Jasig phpCAS 1.1.3 |
Discussion
phpCAS Proxy Mode Multiple Security Vulnerabilities
phpCAS is prone to multiple security vulnerabilities, including multiple cross-site scripting vulnerabilities, a directory-traversal vulnerability, and a privilege-escalation vulnerability.
Attackers can exploit the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials or launch other attacks.
Successfully exploiting the directory-traversal issue allows attackers to view arbitrary local files and directories within the context of the webserver.
Local attackers can exploit the privilege-escalation issue to gain elevated privileges on the affected computer. This may result in the complete compromise of the computer.
The following versions are vulnerable:
phpCAS 1.0.1, 1.1.0, 1.1.1, 1.1.2.
phpCAS is prone to multiple security vulnerabilities, including multiple cross-site scripting vulnerabilities, a directory-traversal vulnerability, and a privilege-escalation vulnerability.
Attackers can exploit the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials or launch other attacks.
Successfully exploiting the directory-traversal issue allows attackers to view arbitrary local files and directories within the context of the webserver.
Local attackers can exploit the privilege-escalation issue to gain elevated privileges on the affected computer. This may result in the complete compromise of the computer.
The following versions are vulnerable:
phpCAS 1.0.1, 1.1.0, 1.1.1, 1.1.2.
Exploit / POC
phpCAS Proxy Mode Multiple Security Vulnerabilities
Attackers can exploit these issues via a browser and readily available commands. To successfully exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues via a browser and readily available commands. To successfully exploit the cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
phpCAS Proxy Mode Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
phpCAS Proxy Mode Multiple Security Vulnerabilities
References:
References:
- #495542 RFP: libcas-php -- CAS client library for PHP (Olivier Berger)
- MSA-10-0016: Multiple phpCAS library vulnerabilities (Moodle)
- phpCAS Homepage (Jasig)
- phpCAS multiple issues (Joachim Fritschi)