Vulnerable Systems:
* Quicksilver Forums version 1.4.2
* PowerDNS Administrator version 1.1.8
* QSF Portal version 1.4.5
The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. execute arbitrary SQL queries by tricking a logged in administrator into visiting a malicious web site.
Workaround:
Do not browse untrusted sites or follow untrusted links while being logged-in to the application.
Disclosure Timeline:
24/02/2010 - Vendor of QSF Portal and PowerDNS Administrator notified.
10/03/2010 - Vendor of Quicksilver Forums notified.
12/03/2010 - Vendor of Quicksilver Forums responds.
17/03/2010 - Public disclosure.