[BMSA-2009-08] Multiple Vulnerabilities in PyForum

看板Bugtraq作者時間16年前 (2009/12/16 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
--Signature=_Tue__15_Dec_2009_10_26_16_+0700_eKScwk_/PXeMKGzI Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: quoted-printable BLUE MOON SECURITY ADVISORY 2009-08 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D :Title: Multiple Vulnerabilities in PyForum :Severity: Critical :Reporter: Hoang Quoc Thinh and Blue Moon Consulting :Products: PyForum v1.0.3 :Fixed in: -- Description ----------- PyForum is a 100% python-based message board system based in the excellent = web2py framework. We have discovered cross site scripting and cross site request forgery vuln= erabilities in PyForum. The first allows arbitrary script to run when a pos= t is viewed. The second allows attackers to submit forms (such as changing = password) automatically without user's knowledge. XSS vulnerability lies in the BBcode parsing in module ``models.parser``. T= he ``img`` and ``url`` tags do not sanitize inputs and hence are susceptibl= e to script injection. CSRF vulnerability lies in the design of this web application. Forms do not= have secure cookies and may be automatically submitted on behalf of the us= er. These bugs are rated at critical because they can be easily exploited and c= ause lost of integrity. These bugs may exist in older versions and in zForum, from which pyForum de= rives, too. Workaround ---------- There is no workaround. Fix --- There is no fix at the moment. Disclosure ---------- Blue Moon Consulting adapts `RFPolicy v2.0 <http://www.wiretrip.net/rfp/pol= icy.html>`_ in notifying vendors. :Initial vendor contact: December 05, 2009: Notice sent to Julio Flores Schwarzbeck (techfuel.net) December 09, 2009: Reminder sent to Julio Flores Schwarzbeck :Vendor response: -- :Further communication: -- :Public disclosure: December 15, 2009 :Exploit code: No exploit code required. Disclaimer ---------- The information provided in this advisory is provided "as is" without warra= nty of any kind. Blue Moon Consulting Co., Ltd disclaims all warranties, ei= ther express or implied, including the warranties of merchantability and fi= tness for a particular purpose. Your use of the information on the advisory= or materials linked from the advisory is at your own risk. Blue Moon Consu= lting Co., Ltd reserves the right to change or update this notice at any ti= me. --Signature=_Tue__15_Dec_2009_10_26_16_+0700_eKScwk_/PXeMKGzI Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (MingW32) iEYEARECAAYFAksnAdgACgkQbKzcTD214ZeihgCghPM9vqQDXC7M379YxVixzhms yboAn3FonHLdWH3kf4UTNZVIeGq008Co =nuqZ -----END PGP SIGNATURE----- --Signature=_Tue__15_Dec_2009_10_26_16_+0700_eKScwk_/PXeMKGzI--
文章代碼(AID): #1B9yxYnm (Bugtraq)