2. MKPGallery mime type vulnerability
3. Blog Template Javascript Filtering Vulnerability
-----------------------------------------
1. MKPortal Multiboard XSS vulnerability in pmpopup.php
There is a XSS vulnerability in the MKPortal PM popup functions. All versions of the MKPortal Multiboard (M0.2 - M1.1Rc1) are affected.
As a temporary measure you can remove pmpopup.php from your server and comment out this line in mkportal/include/functions.php (function header)...
//$pmk_js .= $mklib_board->popup_pm($this->lang['popm1'], $this->lang['popm2'], $this->lang['popm3'], $this->lang['popm4']);This will disable PM popups in the Portal and will neutralize XSS this vulnerability. Hopefully there will be an official patch very soon.
Quote
Advisory ID : FrSIRT/ADV-2006-1485
CVE ID : GENERIC-MAP-NOMATCH
Rated as : Low Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-04-24
Technical Description
Multiple vulnerabilities have been identified in MKPortal, which may be exploited by attackers to execute arbitrary scripting code. These flaws are due to input validation errors in the "include/pmpopup.php" script that does not validate the "u1", "m1", "m2", "m3", and "m4" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
Affected Products
MKPortal version 1.0 and prior
MKPortal version 1.1 RC1 and prior
Solution
The FrSIRT is not aware of any official supplied patch for this issue.
References
http://www.frsirt.co...ories/2006/1485
http://www.nukedx.com/?viewdoc=26
Credits
Vulnerabilities reported by Mustafa Can Bjorn
ChangeLog
2006-04-24 : Initial release
(from http://www.frsirt.co...ries/2006/1485)
CVE ID : GENERIC-MAP-NOMATCH
Rated as : Low Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-04-24
Technical Description
Multiple vulnerabilities have been identified in MKPortal, which may be exploited by attackers to execute arbitrary scripting code. These flaws are due to input validation errors in the "include/pmpopup.php" script that does not validate the "u1", "m1", "m2", "m3", and "m4" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
Affected Products
MKPortal version 1.0 and prior
MKPortal version 1.1 RC1 and prior
Solution
The FrSIRT is not aware of any official supplied patch for this issue.
References
http://www.frsirt.co...ories/2006/1485
http://www.nukedx.com/?viewdoc=26
Credits
Vulnerabilities reported by Mustafa Can Bjorn
ChangeLog
2006-04-24 : Initial release
(from http://www.frsirt.co...ries/2006/1485)


This topic is locked










