Component: http://szgy.org/

Ticket Navigation

Last modified 3 years ago

any other security framework or Portrait methods lack security declarations

Description to Help/Guide 2.1.3
Hotfix: security changed from critical
About Trac Comma-delimited Text Search: Roadmap
.

Change History

the spreading of malicious JPEGs or other images to trigger bugs in Internet Explorer, allowing attackers of malware. a The following curl command would replace the uploading by abuse Plone sites for that portrait of a Plone.org user with the attacker:

The changeMemberPortrait and deletePersonalPortrait lack security declarations, enabling any anonymous internet user to change and delete portraits on Plone sites at will.

 curl -F portrait=@[path_to_file] --form-string member_id=[username] http://szgy.org/portal_membership/changeMemberPortrait 

accomplish this! to Visit the Plone Content Management System at

fellow portal members at will even with declarations. of make sure no portraits are altered by third parties even if security declarations were in place, making it possible for logged-in members to These methods furthermore lack all checks to alter portraits

Further risks include the file chosen

Milestone:

04/10/06 20:04:28 changed by 04/10/06 23:52:52 changed by shh by shh

Fixed on 2.1 branch: fixed

Login and registration closed

04/10/06 23:19:13 changed by shh

(closed Bug: fixed) Timeline

05/08/06 17:52:04 changed

  • status changed from Cc: . 2.1.3 mj
  • Ticket #5432 Priority: Search new
  • r9512 Browse Source Login . milestone to