Liferay Portal Multiple Security Vulnerabilities
BID:67096
Info
Liferay Portal Multiple Security Vulnerabilities
| Bugtraq ID: | 67096 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2014 12:00AM |
| Updated: | Apr 28 2014 12:00AM |
| Credit: | Shitian "Shelton" Zhang, Tomas Polesovsky, Samuel Kong, Mark Jin, and Hong Zhao. |
| Vulnerable: |
Liferay Enterprise Portal 6.0.6 GA Liferay Enterprise Portal 6.0.5 GA Liferay Enterprise Portal 6.0.4 GA Liferay Enterprise Portal 5.3 Liferay Enterprise Portal 5.1.2 Liferay Enterprise Portal 4.4.2 Liferay Enterprise Portal 4.4 Liferay Enterprise Portal 4.3.7 Liferay Enterprise Portal 4.3.6 Liferay Enterprise Portal 4.3.1 Liferay Enterprise Portal 4.3 Liferay Enterprise Portal 4.1.3 Liferay Enterprise Portal 4.1.1 Liferay Enterprise Portal 4.1 Liferay Enterprise Portal 3.6.1 Liferay Enterprise Portal 2.2 .0 Liferay Enterprise Portal 2.1.1 Liferay Enterprise Portal 6.1 GA1 EE Liferay Enterprise Portal 6.1 GA1 CE Liferay Enterprise Portal 6.1 ee Liferay Enterprise Portal 6.1 ce Liferay Enterprise Portal 6.1 Liferay Enterprise Portal 6.0.6 ce Liferay Enterprise Portal 6.0.5 ce Liferay Enterprise Portal 6.0 |
| Not Vulnerable: | |
Discussion
Liferay Portal Multiple Security Vulnerabilities
Liferay Portal is prone to multiple security vulnerabilities including:
1. A cross-site request-forgery vulnerability
2. Multiple HTML-injection vulnerabilities
3. Multiple cross-site scripting vulnerabilities
4. An unauthorized-access vulnerability
An attacker can exploit these vulnerabilities to execute HTML and script code, steal cookie-based authentication credentials, gain unauthorized access, perform unauthorized actions in the context of a user's session or perform unauthorized actions. Other attacks are also possible.
Liferay Portal is prone to multiple security vulnerabilities including:
1. A cross-site request-forgery vulnerability
2. Multiple HTML-injection vulnerabilities
3. Multiple cross-site scripting vulnerabilities
4. An unauthorized-access vulnerability
An attacker can exploit these vulnerabilities to execute HTML and script code, steal cookie-based authentication credentials, gain unauthorized access, perform unauthorized actions in the context of a user's session or perform unauthorized actions. Other attacks are also possible.
Exploit / POC
Liferay Portal Multiple Security Vulnerabilities
Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
Liferay Portal Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.