看板 Bugtraq 關於我們 聯絡資訊
SilverStripe(R) Information Exposure Through Query Strings in GET Request (C= WE-598) - CVE: CVE-2013-2653 - CWE: CWE-598 - Deloitte Argentina Advisory Code: DTTAR-20130002 - Vendor Status: CONFIRMED - Vendor Disclosure Date: May, 8th, 2013. - Public Disclosure Date: August, 1st, 2013. - Vendors Affected: SilverStripe - http://www.silverstripe.org/ - Systems Affected: SilverStripe CMS v3.0.3 - Description: It was observed that the SilverStripe CMS application is susc= eptible to information exposure through query strings in forced GET requests= =2E The objective for a malicious user would be to send a specially crafted = URL to a valid user, in an attempt to trick them into clicking this maliciou= s link and execute the action in the victim=E2=80=99s context. A malicious u= ser may craft a website requesting email and password, where inside an ifram= e an automatic login to the real website could be executed and go by unnotic= ed. - PoC: http://<IP:Port>/Security/LoginForm?AuthenticationMethod=3DMemberA= uthenticator&Email=3D<email>&Password=3D<password>&BackURL=3D%2Fadmin%2Fpage= s&action_dologin=3DLog+in NOTE: A single click to the URL above, allows access to the = admin section of SilverStripe, redirecting the user to http://<IP:Port>/admi= n/pages - Vulnerability Status: in process of being released. - Patch Available: https://github.com/chillu/silverstripe-framework/commit/3= e88c98ca513880e2b43ed7f27ade17fef5d9170 - Fix: Will be available on 3.1 release. - Related Links: Deloitte Argentina - www.deloitte.com/ar - Credits: This vulnerability was found by Fara Rustein from Deloitte Argent= ina (https://twitter.com/FaraRustein). - Feedback: If you have any questions, comments, concerns, updates or sugges= tions please feel free to send them to: frustein@deloitte.com Fara Rustein Senior Consultant, Cyber Security - ERS Deloitte & Co. S.A. Tte. Gral.J.D.Per=C3=B3n 646 - C1038AAN=C2=A0Buenos Aires Argentina Main: +54 11 4320 2700 ext. 8350 | Fax: +54 11 4320 4071 frustein@deloitte.com | www.deloitte.com =EF=81=90 Please consider the environment before printing. =C2=A0 Deloitte se refiere a una o m=C3=A1s de las firmas miembros de Deloitte Touc= he Tohmatsu Limited, una compa=C3=B1=C3=ADa privada del Reino Unido limitada= por garant=C3=ADa, y su red de firmas miembros, cada una como una entidad = =C3=BAnica e independiente y legalmente separada.=C2=A0Una descripci=C3=B3n = detallada de la estructura legal de Deloitte Touche Tohmatsu Limited y sus f= irmas miembros puede verse en el sitio web http://www.deloitte.com/about.= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0La informaci=C3=B3n de este mail es confidencial y concierne = =C3=BAnicamente a la persona a quien est=C3=A1 dirigida. Si este mensaje no = est=C3=A1 dirigido a usted, por favor tenga presente que no tiene autorizaci= =C3=B3n para leer el resto de este e-mail, copiarlo o derivarlo a cualquier = otra persona que no sea aquella a quien est=C3=A1 dirigido. Si recibe este m= ail por error, por favor, avise al remitente, luego de lo cual rogamos a ust= ed destruya el mensaje original. No se puede responsabilizar de ning=C3=BAn = modo a Deloitte & Co. S.A. ni a sus subsidiarias por cualquier consecuencia = o da=C3=B1o que pueda resultar del apropiado y completo env=C3=ADo y recepci= =C3=B3n del contenido de este e-mail. =C2=A0 Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK pri= vate company limited by guarantee, and its network of member firms, each of = which is a legally separate and independent entity. Please see=C2=A0http://w= ww.deloitte.com/about=C2=A0for a detailed description of the legal structure= of Deloitte Touche Tohmatsu Limited and its member firms.=C2=A0 The information in this e-mail is confidential and intended solely for the p= erson to whom it is addressed. If this message is not addressed to you, plea= se be aware that you have no authorization to read the rest of this e-mail, = to copy it or to furnish it to any person other than the addressee. Should y= ou have received this e-mail by mistake, please bring this to the attention = of the sender, after which you are kindly requested to destroy the original = message.=C2=A0Deloitte & Co. S.A. and subsidiaries cannot be held responsibl= e or liable in any way whatsoever for and/or in connection with any conseque= nces and/or damage resulting from the proper and complete dispatch and recei= pt of the content of this e-mail.