NASLDB: Liferay Portal < 6.0.6 Multiple Vulnerabilities
General
ID: 59230
Name: Liferay Portal < 6.0.6 Multiple Vulnerabilities
Summary: Checks the version of Liferay Portal
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS Temporal Vector: CVSS2#E:F/RL:OF/RC:C
Port: 80
Family: CGI abuses
Type: Remote
Description
According to its self-reported version number, the installation of
Liferay Portal hosted on the remote web server is affected by multiple
vulnerabilities :
– An arbitrary file download vulnerability exists when
Apache Tomcat is used, which may allow remote,
authenticated users to download arbitrary files via an
entity declaration in conjunction with an entity
reference, related to an XML External Entity (aka XXE)
issue. (CVE-2011-1502)
– An arbitrary file download vulnerability exists when
Apache Tomcat or Oracle GlassFish is used. The XSL
Content portlet may allow remote, authenticated users to
read arbitrary XSL / XML files via a file:/// URL.
(CVE-2011-1503)
– A cross-site scripting vulnerability exists, which may
allow remote, authenticated users to inject arbitrary
JavaScript or HTML via a blog title. (CVE-2011-1504)
– A cross-site scripting vulnerability exists when Apache
Tomcat is used, which may allow remote, authenticated
users to inject arbitrary JavaScript or HTML via a
message title. (CVE-2011-1570)
– An unspecified vulnerability exists when Apache Tomcat
is used. The XSL Content portlet may allow remote
attackers to execute arbitrary commands via unknown
vectors. (CVE-2011-1571)
Note that Nessus has not tested for the issues, but instead has relied
only on the application’s self-reported version number.
Exploiting
Exploit Available: True
Exploitability Ease: Exploits are available
Sources
CVE: CVE-2011-1502
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2011/03/29
Patch Release: 2011/03/29
Plugin Release: 2012/05/22
Plugin
Version: 1.3
Filename: liferay_6_0_6.nasl
Filesize: 5452 bytes
MD5 Hash: 1f21825f9a767010d00197bf1c32ce2f
Identification: –
Require Keys: www/liferay_portal
Dependencies: "liferay_detect.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













