SiteBar contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the forward parameter upon submission to the command.php script. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. This could be leveraged to direct a user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified
OSVDB:
Web Related
Technical
SiteBar can be made to redirect users to malicious locations, as it makes no checks on the value passed within the forward parameter of the URL, for example:
Upgrade to version 3.3.9 or higher, as it has been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.