SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

SAXON version 5.4 XSS Attack Vulnerability


Arrow  SecurityAlert : 3310
Arrow  CVE : CVE-2007-4862
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : Yes
Arrow  Credit : Jesper Jurcenoks
Arrow  Published : 30.10.2007

Arrow  Affected Software : SAXON version 5.4



Arrow  Advisory Content :  

netVigilance Security Advisory #54

SAXON version 5.4 XSS Attack Vulnerability

Description:

SAXON is a simple accessible online news publishing system for personal and
small corporate site owners. Publish news, using configurable templates, on
any .php page on your site. Publish news on a 'per author' basis. Edit
and/or delete existing news items. Create multiple RSS news feeds
automatically (RSS 0.9, RSS 2.0 and Atom). Post date news items for later
public release. Multiple authors allowed. Ability to configure users as
Standard or Administrators. Ability to add/delete users (Administrators
only). Option to change any user password (Administrators only). Template
creation/deletion/amendment interface. Online setup and configuration.

Successful exploitation requires PHP register_globals set to On and
magic_quotes_gpc set to Off.

External References:

Mitre CVE: CVE-2007-4862

NVD NIST: CVE-2007-4862

OSVDB: Unassigned

BUGTRAQ/BID: Unassigned

Summary:

SAXON is a simple accessible online news publishing system for personal and
small corporate site owners.

Security problems in the product allow attackers to conduct XSS attacks.

Advisory URL:

http://www.netvigilance.com/advisory0054

Release Date:

10/29/2007

CVSS Version 2 Metrics:

Base Metrics:

Exploitability Metrics:

Access Vector:

Network

Access Complexity:

Low

Authentication:

None

Impact Metrics:

Confidentiality Impact:

Partial

Integrity Impact:

Partial

Availability Impact:

Partial

Temporal Metrics:

Exploitability:

Functional

Remediation Level:

Official Fix

Report Confidence:

Confirmed

CVSS Version 2 Vectors:

Base Vector:

"AV:N/AC:L/Au:N/C:P/I:P/A:P"

Temporal Vector:

"E:F/RL:OF/RC:C"

CVSS Version 2 Scores:

Base Score:

7.5

Impact Subscore:

6.4

Exploitability Subscore:

10

Temporal Score:

6.2

SecureScout Testcase ID:

TC 17991

Vulnerable Systems:

SAXON version 5.4

Vulnerability Type:

XSS (Cross-Site Scripting) to force a web-site to display malicious
contents to the target, by sending a specially crafted request to the
web-site. The vulnerable web-site is not the target of attack but is used
as a tool for the hacker in the attack of the victim.

Vendor:

Quirm

Vendor Status:

The Vendor has confirmed the problem and has release new version 5.41 that
addresses the problem. New version of product was tested and we can confirm
that all vulnerabilities were solved. For more information see vendor
announcement. To download the latest version go to vendors product download
area.

Workaround:

From netVigilance:

In the php.ini file set register_globals = Off.

From vendor:

Modify .htaccess file to include 'php_flag register_globals off' directive
(this will work only for the Apache servers).

Example:

REQUEST:

http://[TARGET]/[PRODUCT
DIRECTORY]/admin/menu.php?config[news_url]="><script>alert(document.cook
ies)</script>

REPLY:

will execute <script>alert(document.cookie)</script>

Credits:

Jesper Jurcenoks

Co-founder netVigilance, Inc

www.netvigilance.com






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.