the last unbiased stronghold

OpenX Security Advisory - XSS / SQL Injection / Directory Traversal

OpenX Security Advisory - XSS / SQL Injection / Directory Traversal
Posted Jan 30, 2009
Authored by Matteo Beccati | Site openx.org

OpenX versions 2.4.9 and below and versions 2.6.3 and below suffer from cross site scripting, SQL injection, and directory traversal vulnerabilities.

tags | advisory, vulnerability, xss, sql injection
advisories | CVE-2009-0291
MD5 | 37ebfa658364aa9192a949f7bac1cbcd

OpenX Security Advisory - XSS / SQL Injection / Directory Traversal

Change Mirror Download
========================================================================
OpenX security advisory OPENX-SA-2009-001
------------------------------------------------------------------------
Advisory ID: OPENX-SA-2009-001
Date: 2009-Jan-30
Security risk: Moderately critical
Applications affetced: OpenX
Versions affected: <= 2.4.9, <= 2.6.3
Versions not affected: >= 2.4.10, >= 2.6.4
========================================================================


========================================================================
Multiple vulnerabilities: XSS, SQL inection, directory traversal
========================================================================

Description
-----------
A security review of OpenX 2.6.3 was recently being conducted on Openx
2.6.3 by Sarid Harper on behalf of Secunia and reported to us. One of
the vulnerabilities was also independently discovered by Charlie Briggs
and disclosed on milw0rm.com, forcing Secunia to publish the research
results before our fix releases were ready.

The review contains a list of 22 items for multiple vulnerabilities
ranging from XSS to SQL injection to directory traversal. Some are only
exploitable by authenticated users, others can be conducted by
unauthenticated users.

All the the items were fixed in OpenX 2.6 and backported to 2.4 when
applicable. New versions of both OpenX 2.6 and 2.4 have been released.

Solution
--------
- Upgrade to OpenX 2.4.10 or 2.6.4

References
----------
- http://secunia.com/advisories/32197/
- http://www.milw0rm.com/exploits/7883
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0291

Timeline
--------
2009-Jan-20: Secunia reported the security review results to OpenX
2009-Jan-20: OpenX started investigation and scheduled the fixes
according to the company release plans
2009-Jan-26: the fc.php MAX_type vulnerability was independently
discovered and disclosed
2009-Jan-27: an OpenX user reported the link to our forums
2009-Jan-27: Secunia was forced to disclose the entire review
2009-Jan-29: OpenX 2.4.10 and 2.6.4 were released by OpenX


Contact informations
====================

The security contact for OpenX can be reached at:
<security AT openx DOT org>


Best regards

--
Matteo Beccati

OpenX - http://www.openx.org

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close