Ektron CMS 8.5.0 Multiple Vulnerabilities
PHP:
Release Date. Â Â Â Â Â Â Â 05-Sep-2012
Last Update. Â Â Â Â Â Â Â - Â Â Â Â Â Â
Vendor Notification Date. Â 07-May-2012
Product. Â Â Â Â Â Â Â Â Â Ektron CMS
Platform. Â Â Â Â Â Â Â Â Â ASP.NET
Affected versions. Â Â Â Â Ektron CMS version 8.5.0 and possibly others
Severity Rating. Â Â Â Â Â High
Impact. Â Â Â Â Â Â Â Â Â Â Exposure of sensitive information
             Exposure of system information
             System Access
Attack Vector. Â Â Â Â Â Â Remote without authentication
Solution Status. Â Â Â Â Â Fixed in version 8.6
             (not verified by SOS)
CVE reference. Â Â Â Â Â Â CVE - not yet assigned
Details.
The web application is vulnerable to multiple security
vulnerabilities, such as Unauthenticated File Upload and
XML eXternal Entities (XXE) injection.
1.Unauthenticated File Upload:
The form /WorkArea/Upload.aspx does not require authentication
to upload a file. By issuing a POST request with a webshell
embedded in a JPEG image and specifying the ASPX extension it is
possible to upload ASPX code to /uploadedimages/. The ASPX code
is placed in the comment section of the JPEG so that it survives
image resizing.
2.XXE Injection:
The XML parser at /WorkArea/Blogs/xmlrpc.aspx is vulnerable to
XML external entity attacks which can be used to Scan behind
perimeter firewalls or possibly include files from the local file
system e.g.
<!DOCTYPE scan [<!ENTITY test SYSTEM "http://localhost:22">]>
<scan>&test;</scan>
Solution.
Upgrade to version 8.6 and remove the /WorkArea/Blogs/xmlrpc.aspx file.
# Â 0day.today [2017-11-15] Â #
