MySource Matrix 3.8 and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the 'sq_remote_page_url' or base64 encoded 'sq_content_src' parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Vendor Verified
Technical
Note: The vendor does not consider this a vulnerability. In versions 3.8 or later, the function name was changed and the URL is Base64 encoded as a method of obscuring it.
Solution
The vendor has released new functionality which whitelists accepted Base64 encoded URLs, so that 3rd party domains cannot be used unless explicitly permitted.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.