oss-sec mailing list archives
CVE request: POSH multiple vulnerabilities
From: Damien Cauquil <d.cauquil () sysdream com>
Date: Wed, 26 Feb 2014 14:03:16 +0100
We recently found four vulnerabilities in POSH web application, including: 1. Unauthenticated SQL injection vulnerability affecting all POSH 3.X versions prior to 3.3.0 An unauthenticated SQL injection is present and can be exploited to extract data stored in database. 2. Design vulnerability affecting all POSH 3.X versions (no fix yet) There is a design vulnerability in the way POSH stores users credentials in the browser's cookie (POSH stores every user's password md5 hash inside an unsecure cookie) 3. Arbitrary url redirection affecting all POSH 3.X versions (no fix yet) This vulnerability is hardly exploitable but shows a lack of user input validation. 4. Cross-Site scripting vulnerability affecting all POSH 3.X versions (no fix yet) References: * advisory: http://www.sysdream.com/system/files/POSH-3.2.1-advisory.pdf * POSH 3.3.0 release: http://sourceforge.net/projects/posh/files/Posh%20portal/posh%203.3.0/ * svn commit url: http://sourceforge.net/p/posh/svn/3540/ We would like to request 4 CVEs for these vulnerabilities. -- Damien Cauquil R&D Director CHFI | CEH | ECSA | CEI Sysdream 108 avenue Gabriel Péri 93400 Saint Ouen Tel: +33 (0) 1 78 76 58 21 www.sysdream.com
Current thread:
- CVE request: POSH multiple vulnerabilities Damien Cauquil (Feb 26)