AntiSnatchOr.com - Keep It Simple Stupid

  • about
  • services
  • security advisories
  • contact
  • publications
  • my books
Home › Blogs › antisnatchor's blog

Pentaho 1.7.0.1062 Multiple Vulnerabilities

antisnatchor — 20 June, 2009 - 23:25

A lot of months ago I was researching bugs in the excellent Pentaho Business Intelligence platform (with bundled jboss). I've found the following: A) Reflected XSS B) Password field with autocomplete enabled C) Disclosure of Session Tokens in URL More infos here: [http://jira.pentaho.com/browse/BISERVER-2698?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel] After 6 months (SIX! it remembers me David Litchfield and Oracle :) ) Pentaho developers partially fixed everything. I've not disclosed this before because I'm trying to follow Responsible Disclosure more as I can... Is that the best? Well, sometimes... That's responsible disclosure
  • Advisories
  • pentaho
  • antisnatchor's blog

Recent blog posts

  • BeEF on OpenBSD
  • Meet BeEF at DeepSec 2011
  • My BeEF talk at CONFidence 2011
  • JBoss JMX Deploy Exploit
  • Enumerate potential DOM-based XSS vulnerable code
  • I will speak at Confidence 2011
  • DotCloud Beta Multiple Vulnerabilities
  • OpenCMS <= 7.5.3 multiple vulnerabilities
  • OpenCMS public vuln disclosure at the end of March
  • Drupal <= 6.20 insecure Captcha defaults PoC
more

Who's online

There are currently 0 users and 1 guest online.

Powered by Drupal, an open source content management system
  • about
  • services
  • security advisories
  • contact
  • publications
  • my books