Aerosol Posted March 18, 2015 Report Posted March 18, 2015 *Innovative WebPAC Pro 2.0 Unvalidated Redirects and Forwards (URLRedirection) Security Vulnerabilities*Exploit Title: Innovative WebPAC Pro 2.0 /showres url parameter URLRedirection Security VulnerabilitiesVendor: Innovative Interfaces IncProduct: WebPAC ProVulnerable Versions: 2.0Tested Version: 2.0Advisory Publication: March 14, 2015Latest Update: March 14, 2015Vulnerability Type: URL Redirection to Untrusted Site ('Open Redirect')[CWE-601]CVE Reference: *Impact CVSS Severity (version 2.0):CVSS v2 Base Score: 5.8 (MEDIUM) (AV:N/AC:M/Au:N/C:P/I:P/A:N) (legend)Impact Subscore: 4.9Exploitability Subscore: 8.6Discover and Author: Wang Jing [CCRG, Nanyang Technological University(NTU), Singapore]*Suggestion Details:**(1) Vendor & Product Description:**Vendor:*Innovative Interfaces Inc*Product & Version:*WebPAC Pro2.0*Vendor URL & Download:*WebPAC Pro can be got from here,http://www.iii.com/products/webpac_pro.shtmlhttp://lj.libraryjournal.com/2005/12/ljarchives/innovative-releasing-webpac-pro/*Libraries that have installed WebPac Pro:*https://wiki.library.oregonstate.edu/confluence/display/WebOPAC/Libraries+that+have+installed+WebPac+Pro*Product Introduction Overview:*"Today, some libraries want to enhance their online presence in ways thatgo beyond the traditional OPAC and the "library portal" model to betterintegrate the latest Web functionality. With WebPAC Pro, libraries will beable to take advantage of the latest Web technologies and engage Web-savvyusers more effectively than ever before. WebPAC Pro is a complete update ofthe Web OPAC interface""WebPAC Pro breaks through the functional and design limitations of thetraditional online catalog. Its solid technology framework supports toolsfor patron access such as Spell Check; integrated Really Simple Syndication(RSS) feeds; a suite of products for seamless Campus Computing; and deepcontrol over information content and presentation with Cascading StyleSheets (CSS). WebPAC Pro is also a platform for participation whenintegrated with Innovative's Patron Ratings features and Community Reviewsproduct. What's more, with WebPAC Pro's RightResult™ search technology, themost relevant materials display at the top so patrons get to the specificitems or topics they want to explore immediately. WebPAC Pro can alsointerconnect with Innovative's discovery services platform, Encore. And forelegant access through Blackberry® Storm™ or iPhone™, the AirPAC providescatalog searching, item requesting, and more."*(2) Vulnerability Details:*WebPAC Pro web application has a security bug problem. It can be exploitedby Unvalidated Redirects and Forwards (URL Redirection) attacks. This couldallow a user to create a specially crafted URL, that if clicked, wouldredirect a victim from the intended legitimate web site to an arbitrary website of the attacker's choosing. Such attacks are useful as the crafted URLinitially appear to be a web page of a trusted site. This could beleveraged to direct an unsuspecting user to a web page containing attacksthat target client side software such as a web browser or documentrendering programs.Other Innovative Interfaces products vulnerabilities have been found bysome other bug hunter researchers before. Innovative has patched some ofthem. NVD is the U.S. government repository of standards basedvulnerability management data (This data enables automation ofvulnerability management, security measurement, and compliance (e.g.FISMA)). It has published suggestions, advisories, solutions related toInnovative vulnerabilities.*(2.1) *The first code programming flaw occurs at "showres?" page with"&url" parameter.*References:*http://tetraph.com/security/open-redirect/innovative-webpac-pro-2-0-unvalidated-redirects-and-forwards-url-redirection-security-vulnerabilities/http://securityrelated.blogspot.com/2015/03/innovative-webpac-pro-20-unvalidated.htmlhttp://www.inzeed.com/kaleidoscope/computer-web-security/innovative-webpac-pro-2-0-unvalidated-redirects-and-forwards-url-redirection-security-vulnerabilities/http://diebiyi.com/articles/%E5%AE%89%E5%85%A8/innovative-webpac-pro-2-0-unvalidated-redirects-and-forwards-url-redirection-security-vulnerabilities/https://infoswift.wordpress.com/2015/03/14/innovative-webpac-pro-2-0-unvalidated-redirects-and-forwards-url-redirection-security-vulnerabilities/http://marc.info/?l=full-disclosure&m=142527148510581&w=4http://en.hackdig.com/wap/?id=17054--Wang Jing,Division of Mathematical Sciences (MAS),School of Physical and Mathematical Sciences (SPMS),Nanyang Technological University (NTU),Singapore.http://www.tetraph.com/wangjing/https://twitter.com/tetraphibiousSource Quote