Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-1119

Potential DoS attack using Login or Search forms

    XMLWordPrintable

Details

    • Bug
    • Resolution: Cannot Reproduce
    • Major
    • None
    • 1.0 RC1
    • Storage
    • None
    • security
    • High

    Description

      Reported by Pablo Oliveira:

      It's possible for a user to modify the HQL that gets executed (in the Login form or in Search forms for example). For example, it's possible, in the login form type the following instead of the user name:

      \'  )   AND 5=BENCHMARK(1000000000,MD5(CHAR(116)))  --  
      

      This example will keep the SQL server busy for a long time...

      Attachments

        Activity

          People

            calebjamesdelisle CalebJamesDeLisle
            vmassol Vincent Massol
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: