Symphony Multiple Remote Security Vulnerabilities
BID:56094
Info
Symphony Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 56094 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2012 12:00AM |
| Updated: | Mar 19 2015 09:24AM |
| Credit: | Wireghoul |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symphony Multiple Remote Security Vulnerabilities
Symphony is prone to following multiple remote security vulnerabilities:
1. An authentication-bypass vulnerability
2. Multiple cross-site-scripting vulnerabilities
3. An HTML-injection vulnerability
4. Multiple SQL-injection vulnerabilities
An attacker may leverage these issues to run malicious HTML and script codes in the context of the affected browser, steal cookie-based authentication credentials, to gain unauthorized access to the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symphony 2.3 is vulnerable; other versions may also be affected.
Symphony is prone to following multiple remote security vulnerabilities:
1. An authentication-bypass vulnerability
2. Multiple cross-site-scripting vulnerabilities
3. An HTML-injection vulnerability
4. Multiple SQL-injection vulnerabilities
An attacker may leverage these issues to run malicious HTML and script codes in the context of the affected browser, steal cookie-based authentication credentials, to gain unauthorized access to the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Symphony 2.3 is vulnerable; other versions may also be affected.
Exploit / POC
Symphony Multiple Remote Security Vulnerabilities
An attacker can exploit these issues through a browser. An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues.
The following example URI is available:
http://www.example.com/path/symphony/bluePRINTs/page/edit/0%29+union+select+1,2,username,password,5,auth_token_active,7,8,9+from+sym_authors+where+id+=+1+--+/
An attacker can exploit these issues through a browser. An attacker must trick an unsuspecting victim into following a malicious URI to exploit the cross-site scripting issues.
The following example URI is available:
http://www.example.com/path/symphony/bluePRINTs/page/edit/0%29+union+select+1,2,username,password,5,auth_token_active,7,8,9+from+sym_authors+where+id+=+1+--+/
Solution / Fix
Symphony Multiple Remote Security Vulnerabilities
Solution:
Reportedly, the issue is fixed. However, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed. However, Symantec has not confirmed this. Please contact the vendor for more information.
References
Symphony Multiple Remote Security Vulnerabilities
References:
References: