Hello list!
I want to warn you about vulnerabilities in Moxiecode Image Manager
(MCImageManager). This is commercial plugin for TinyMCE. It concerns as
MCImageManager, as all web applications which have MCImageManager in their
bundle.
These are Content Spoofing, Cross-Site Scripting and Full Path Disclosure
vulnerabilities. About Content Spoofing and Cross-Site Scripting
vulnerabilities in flvPlayer I informed developer already in October 2011
(it was part of Media plugin for TinyMCE) and disclosed them in November.
After my informing he fixed these holes in November 2011 in Media plugin.
But he forgot to fix them in MCImageManager plugin.
-------------------------
Affected products:
-------------------------
Vulnerable are Moxiecode Image Manager 3.1.5 and previous versions.
-------------------------
Affected vendors:
-------------------------
Moxiecode
http://www.moxiecode.com
----------
Details:
----------
Content Spoofing (WASC-12):
Flash-file flvPlayer.swf accepts arbitrary addresses in parameter flvToPlay
and startImage, which allows to spoof content of flash - i.e. by setting
addresses of video and/or image files from other site.
http://site/tiny_mce/plugins/imagemanager/pages/im/flvplayer/flvPlayer.swf?flvToPlay=1.flv
http://site/tiny_mce/plugins/imagemanager/pages/im/flvplayer/flvPlayer.swf?autoStart=false&startImage=1.jpg
http://site/tiny_mce/plugins/imagemanager/pages/im/flvplayer/flvPlayer.swf?flvToPlay=1.flv&autoStart=false&startImage=1.jpg
Flash-file flvPlayer.swf accepts arbitrary addresses in parameter flvToPlay,
which allows to spoof content of flash - i.e. by setting address of playlist
file from other site (parameters thumbnail and url in xml-file accept
arbitrary addresses).
http://site/tiny_mce/plugins/imagemanager/pages/im/flvplayer/flvPlayer.swf?flvToPlay=1.xml
File 1.xml: