Orbeon Forms XML Injection Vulnerability
BID:47362
Info
Orbeon Forms XML Injection Vulnerability
| Bugtraq ID: | 47362 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3260 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 2011 12:00AM |
| Updated: | Apr 14 2011 12:00AM |
| Credit: | Daniel Grzelak and Rohan Stelling |
| Vulnerable: |
Orbeon Orbeon Forms 3.8 |
| Not Vulnerable: |
Orbeon Orbeon Forms 3.9 |
Discussion
Orbeon Forms XML Injection Vulnerability
Orbeon Forms is prone to an XML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attackers can exploit this issue to access internal network resources or to scan networks.
Orbeon Forms versions prior to 3.9 are vulnerable.
Orbeon Forms is prone to an XML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attackers can exploit this issue to access internal network resources or to scan networks.
Orbeon Forms versions prior to 3.9 are vulnerable.
Exploit / POC
Orbeon Forms XML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Orbeon Forms XML Injection Vulnerability
Solution:
The vendor has released an update. Please see the refereces for more information.
Solution:
The vendor has released an update. Please see the refereces for more information.
References
Orbeon Forms XML Injection Vulnerability
References:
References:
- Orbeon Forms 3.9 (Orbeon)
- Orbeon Forms Homepage (Orbeon)