Document Title: =============== BitWeaver Framework v2.8.1 - Multiple Web Vulnerabilities Release Date: ============= 2011-07-31 Vulnerability Laboratory ID (VL-ID): ==================================== 71 Product & Service Introduction: =============================== bitweaver is an application framework for content management. It is a fully functional web application and CMS, and is used to power every page on this site. It is truly open source, community driven, object oriented, and written in PHP. We use Smarty Templates and ADOdb to support many databases including Postgres, Firebird, Oracle, and MySQL. (Copy of the Vendor Homepage: http://www.bitweaver.org/) Abstract Advisory Information: ============================== Vulnerability Lab Team discovered multiple Web Vulnerabilities for the Bitweaver 2.8.1 Framework. Vulnerability Disclosure Timeline: ================================== 2011-07-31: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== High Technical Details & Description: ================================ 1.1 Multiple Input Validation Vulnerabilities are detected on bitweaver 2.8.1. A remote attacker is able to implement malicious persistent script codes on application-side. The successful exploitation of the vulnerability can lead to session hijacking & stable content manipulation. Vulnerable Module(s): [+] Graph options - Site usage Chart [+] Stencil Records - Search Options [+] ShoutBox - Message Validation Pictures: ../xss.png ../ive.png 1.2 A remote sql injection vulnerability is detected on the bitweaver v2.8.1 CMS. Remote attackers can inject/execute own sql statement on the vulnerable application dbms. Vulnerable Module(s): [+] Listing & Event Listing Pictures: ../sql1.png ../sql2.png ../sql3.png Proof of Concept (PoC): ======================= For demonstration ... 1.1 Vulnerable Module: PoC: >"