家庭小木屋

家是什么?众说纷纭。社会学家说,家是社会的最小细胞;婚姻学家说,家是风雨相依的两人世界;文学家说,家是宝盖下面养着的一群猪……究竟什么是家呢?记得在一个朋友的结婚典礼上司仪饱含深情的那句话:家不是讲理的地方,家不是放钱的地方,家不是两个人凑合过日子的地方……

IT 计算机信息网络安全技术:

VuFind 1.0 Reflected XSS (Cross-site Scripting) Application 0-Day Web Security Bug



Exploit Title: VuFind Results? &lookfor parameter Reflected XSS Web Security Vulnerability

Product: VuFind

Vendor: VuFind

Vulnerable Versions: 1.0

Tested Version: 1.0

Advisory Publication: September 20, 2015

Latest Update: September 25, 2015

Vulnerability Type: Cross-Site Scripting [CWE-79]

CVE Reference:

Impact CVSS Severity (version 2.0):

CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)

Impact Subscore: 2.9

Exploitability Subscore: 8.6

CVSS Version 2 Metrics:

Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism

Access Complexity: Medium

Authentication: Not required to exploit

Impact Type: Allows unauthorized modification

Discover and Reporter: Wang Jing [School of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore] (@justqdjing)









Caution Details:



(1) Vendor & Product Description:



Vendor:

VuFind




Product & Vulnerable Versions:

VuFind

1.0




Vendor URL & Download:

Product can be obtained from here,
http://sourceforge.net/p/vufind/news/





Product Introduction Overview:

"VuFind is a library resource portal designed and developed for libraries by libraries. The goal of VuFind is to enable your users to search and browse through all of your library's resources by replacing the traditional OPAC to include: Catalog Records, Locally Cached Journals, Digital Library Items, Institutional Repository, Institutional Bibliography, Other Library Collections and Resources. VuFind is completely modular so you can implement just the basic system, or all of the components. And since it's open source, you can modify the modules to best fit your need or you can add new modules to extend your resource offerings. VuFind runs on Solr Energy. Apache Solr, an open source search engine, offers amazing performance and scalability to allow for VuFind to respond to search queries in milliseconds time. It has the ability to be distributed if you need to spread the load of the catalog over many servers or in a server farm environment. VuFind is offered for free through the GPL open source license. This means that you can use the software for free. You can modify the software and share your successes with the community! Take a look at our VuFind Installations Wiki page to see how a variety of organizations have taken advantage of VuFind's flexibility. If you are already using VuFind, feel free to edit the page and share your accomplishments. "







(2) Vulnerability Details:

VuFind web application has a computer security problem. Hackers can exploit it by reflected XSS cyber attacks. This may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.


Several other similar products 0-day vulnerabilities have been found by some other bug researchers before. VuFind has patched some of them. "scip AG was founded in 2002. We are driven by innovation, sustainability, transparency, and enjoyment of our work. We are completely self-funded and are thus in the comfortable position to provide completely independent and neutral services. Our staff consists of highly specialized experts who focus on the topic information security and continuously further their expertise through advanced training".



(2.1) The code flaw occurs at "lookfor?" parameter in "/vufind/Resource/Results?" page.


Some other researcher has reported a similar vulnerability here and VuFind has patched it.
https://vufind.org/jira/si/jira.issueviews:issue-html/VUFIND-54/VUFIND-54.html








(3) Solution:

Update to new version.









  References:
  http://tetraph.com/security/xss-vulnerability/vufind-xss/
  http://russiapost.blogspot.ru/2015/09/vufind-xss-issue.html
  https://infoswift.wordpress.com/2015/09/25/vufind-issue/
  http://www.openwall.com/lists/oss-security/2015/09/25/2
  http://whitehatview.tumblr.com/post/129834589981/vufind-xss-bugs 
  http://itsecurity.lofter.com/post/1cfbf9e7_854cb25 
  https://progressive-comp.com/?l=oss-security&m=144316469829656&w=1
  http://essayjeans.blog.163.com/blog/static/23717307420158253407863/
  http://seclists.org/oss-sec/2015/q3/639
  http://frenchairing.blogspot.fr/2015/09/vufind-bug.html
  https://itswift.wordpress.com/2015/09/22/vufind-0day/
  http://permalink.gmane.org/gmane.comp.security.oss.general/17836



评论

热度(13)

  1. 家庭小木屋IT 计算机信息网络安全技术 转载了此图片
  2. 谷雨 醉心 冬小麦點滴的記錄 转载了此图片
  3. 琐事,日常之事點滴的記錄 转载了此图片
  4. 點滴的記錄IT 计算机&信息网络 技术 转载了此图片
  5. 计算机网络技术白帽子安全 转载了此图片  到 IT 计算机&信息网络 技术
  6. 计算机网络技术白帽子安全 转载了此图片
  7. 白帽子安全IT 计算机信息网络安全技术 转载了此图片