TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities
BID:50306
Info
TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities
| Bugtraq ID: | 50306 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2011 12:00AM |
| Updated: | Jan 13 2012 05:20PM |
| Credit: | TYPO3 Security Team |
| Vulnerable: |
Typo3 pmkslimbox 3.1.0 Typo3 pmkshadowbox 3.2.0 |
| Not Vulnerable: |
Typo3 pmkshadowbox 3.2.1 |
Discussion
TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities
TYPO3 pmkshadowbox and pmkslimbox extensions are prone to an arbitrary file download and a cross-site scripting vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker can exploit the file download issue to download arbitrary files within the context of the webserver process. Information obtained may aid in further attacks.
An attacker may leverage the cross-site scripting issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to pmkshadowbox 3.2.0 and pmkslimbox 3.1.0 are vulnerable.
TYPO3 pmkshadowbox and pmkslimbox extensions are prone to an arbitrary file download and a cross-site scripting vulnerability because they fail to sufficiently sanitize user-supplied data.
An attacker can exploit the file download issue to download arbitrary files within the context of the webserver process. Information obtained may aid in further attacks.
An attacker may leverage the cross-site scripting issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to pmkshadowbox 3.2.0 and pmkslimbox 3.1.0 are vulnerable.
Exploit / POC
TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities
An attacker can exploit the file download issue with a browser. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit the file download issue with a browser. To exploit a cross-site scripting issue the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
TYPO3 pmkshadowbox and pmkslimbox Cross Site Scripting and Arbitrary File Download Vulnerabilities
References:
References: