Umbraco contains an open proxy weakness. The issue is triggered when input passed via the 'URL' parameter is not properly sanitized before being used in the FeedProxy.aspx script. This may allow an attacker to cause a denial of service or potentially bypass access restrictions or perform an XSS or phishing attack.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Workaround,
Upgrade
Exploit:
Exploit Private
Disclosure:
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 5 or higher, as it has been reported to fix this vulnerability. It is also possible to temporarily work around the flaw by implementing the following workaround: Delete the FeedProxy.aspx script.