Open-Realty Multiple HTML Injection and Cross Site Request Forgery Vulnerabilities
BID:57043
Info
Open-Realty Multiple HTML Injection and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 57043 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2012 12:00AM |
| Updated: | Dec 25 2012 12:00AM |
| Credit: | Aung Khant |
| Vulnerable: |
Open-Realty Open-Realty 3.1.5 Open-Realty Open-Realty 3.0.3 Open-Realty Open-Realty 3.0.4 |
| Not Vulnerable: | |
Discussion
Open-Realty Multiple HTML Injection and Cross Site Request Forgery Vulnerabilities
Open-Realty is prone to multiple HTML-injection vulnerabilities and a cross-site request forgery vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to perform certain unauthorized actions, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Open-Realty is prone to multiple HTML-injection vulnerabilities and a cross-site request forgery vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to perform certain unauthorized actions, execute arbitrary script or HTML code within the context of the browser, and steal cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Open-Realty Multiple HTML Injection and Cross Site Request Forgery Vulnerabilities
An attacker can exploit HTML-injection issues through a browser.
To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
An attacker can exploit HTML-injection issues through a browser.
To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
Solution / Fix
Open-Realty Multiple HTML Injection and Cross Site Request Forgery Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Open-Realty Multiple HTML Injection and Cross Site Request Forgery Vulnerabilities
References:
References:
- Open-Realty CMS 3.x | Cross Site Request Forgery (CSRF) Vulnerability (Aung Khant)
- Open-Realty CMS 3.x | Persistent Cross Site Scripting (XSS) Vulnerability (Aung Khant)
- Open-Realty Homepage (Open-Realty)