Liferay Portal Multiple Security Vulnerabilities
BID:47082
Info
Liferay Portal Multiple Security Vulnerabilities
| Bugtraq ID: | 47082 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 29 2011 12:00AM |
| Updated: | Apr 09 2012 11:10AM |
| Credit: | Amos Fong; Lawrence Lee; Jonas Choi; Nicolas Gregoire. |
| Vulnerable: |
Liferay Enterprise Portal 6.0.5 GA |
| Not Vulnerable: |
Liferay Enterprise Portal 6.0.6 GA |
Discussion
Liferay Portal Multiple Security Vulnerabilities
Liferay Portal is prone to multiple security vulnerabilities including a cross-site scripting vulnerability, multiple information-disclosure vulnerabilities, and a remote command-execution vulnerability.
An attacker may leverage these issues to obtain potentially sensitive information, to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or to execute arbitrary commands in the context of the affected application. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Liferay Portal 6.0.5 GA is vulnerable; other versions may also be affected.
Liferay Portal is prone to multiple security vulnerabilities including a cross-site scripting vulnerability, multiple information-disclosure vulnerabilities, and a remote command-execution vulnerability.
An attacker may leverage these issues to obtain potentially sensitive information, to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or to execute arbitrary commands in the context of the affected application. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Liferay Portal 6.0.5 GA is vulnerable; other versions may also be affected.
Exploit / POC
Liferay Portal Multiple Security Vulnerabilities
An attacker can exploit this issue via a browser. For the cross-site scripting issues an attacker must entice unsuspecting users to follow a malicious URI.
The following exploit is available:
An attacker can exploit this issue via a browser. For the cross-site scripting issues an attacker must entice unsuspecting users to follow a malicious URI.
The following exploit is available:
Solution / Fix
Liferay Portal Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Liferay Portal Multiple Security Vulnerabilities
References:
References:
- CVE requests : Liferay 6.0.6 (Nicolas Grégoire)
- Liferay Portal Product Page (Liferay)
- Release Notes - PUBLIC - Liferay Portal Community Edition - Version 6.0.6 GA - H (Liferay)