REDHAT-BUG-591701: Medium severity xinha wysiwyg editor vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1916 to the following vulnerability:
Name: CVE-2010-1916 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1916 Assigned: 20100511 Reference: MISC: http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html Reference: MISC: http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html
The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backendconfigsecretkeylocation and backendconfighash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backenddata and backenddata[keylocation] variables, which are not properly handled by the xinhareadpasseddata function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.
The upstream bug report [1] has links to patches to correct this issue.
[1] http://trac.xinha.org/ticket/1518
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-591701?
The severity of REDHAT-BUG-591701 is categorized due to a configuration injection vulnerability that can lead to unauthorized access or control.
How do I fix REDHAT-BUG-591701?
To fix REDHAT-BUG-591701, upgrade the Xinha WYSIWYG editor to a version later than 0.96 Beta 2 and Serendipity to version greater than 1.5.2.
What software is affected by REDHAT-BUG-591701?
The affected software includes Xinha WYSIWYG editor versions up to 0.96 Beta 2 and Serendipity versions up to 1.5.2.
What type of vulnerability is REDHAT-BUG-591701?
REDHAT-BUG-591701 is a configuration injection vulnerability that can exploit the WYSIWYG editor functionality.
Is there a workaround for REDHAT-BUG-591701?
There are no specific workarounds mentioned for REDHAT-BUG-591701; the recommended action is to apply the available updates.