Open Web Analytics < 1.5.6 Multiple Vulnerabilities

high Nessus Plugin ID 74189

Synopsis

The remote web server contains a web application that is affected by multiple vulnerabilities.

Description

According to its banner, the version of Open Web Analytics installed on the remote host is prior to version 1.5.6. It is, therefore, affected by the following vulnerabilities :

- A cross-site scripting flaw exists with the login page where input to the 'owa_user_id' parameter is not properly sanitized. This could allow a remote attacker, with a specially crafted request, to execute arbitrary code within the browser / server trust relationship.
(CVE-2014-1456)

- Multiple cross-site scripting flaws exist with the General Configuration Options page where multiple parameters are not properly sanitized. This could allow a remote attacker, with a specially crafted request, to execute arbitrary code within the browser / server trust relationship.

- A cross-site request forgery exists with the cross-site request forgery prevention scheme where the nonce values are not random enough. This could allow a context-dependent attacker, with a specially crafted link, to trick a user into giving the attacker access to sensitive actions. (CVE-2014-1457)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Open Web Analytics 1.5.6 or later.

See Also

http://www.secureworks.com/advisories/SWRX-2014-004/SWRX-2014-004.pdf

http://www.secureworks.com/advisories/SWRX-2014-005/SWRX-2014-005.pdf

http://www.secureworks.com/advisories/SWRX-2014-006/SWRX-2014-006.pdf

http://www.nessus.org/u?9fbbd43d

http://www.openwebanalytics.com/?p=384

Plugin Details

Severity: High

ID: 74189

File Name: open_web_analytics_1_5_6.nasl

Version: 1.10

Type: remote

Family: CGI abuses

Published: 5/27/2014

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2014-1457

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:openwebanalytics:open_web_analytics

Required KB Items: www/PHP, Settings/ParanoidReport, www/openwebanalytics

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No exploit is required

Patch Publication Date: 2/1/2014

Vulnerability Publication Date: 2/1/2014

Reference Information

CVE: CVE-2014-1456, CVE-2014-1457

BID: 65571, 65573

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990