|
|
|
>>
VUPEN Security / Public Mailing Lists Mirror |
Assigned : VUPEN/ADV-2005-2419
From : alireza hassani <trueend5 at yahoo.com>
Subject : [KAPDA::#12] - ekinboard XSS and HTML Injection
Date : 2005-11-14
Original Message
[KAPDA::#12] - ekinboard XSS and HTML Injection KAPDA New advisory Vendor: http://www.ekinboard.com Vulnerable Version: 1.0.3 Bug: XSS and HTML Injection Exploitation: Remote with browser
Description: -------------------- ekinboard is an open source forum software designed and programmed by ekindesigns. It is constantly being updated and is always getting easier to use!
Vulnerability: -------------------- HTML Injection: The software does not properly filter HTML tags in post titles that may allow a remote user to inject HTML/javascript codes. The hostile code may be rendered in the web browser of the victim user who will visit the board (persistent).
XSS: XSS Vulnerability in 'profile.php' "user rating" that may allow a remote user to launch cross-site scripting attacks. This issue could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected Web site.(victim must be logged in to enable rating)
Demonstration URL : -------------------- http://localhost/ekinboard/profile.php?id=2'%3E%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
Solution: -------------------- There is no vendor-supplied patch for this issue at this time.
More Detail: -------------------- http://irannetjob.com/content/view/162/28/
Credit : -------------------- Discovered & released by trueend5 (trueend5 kapda ir) Security Science Researchers Institute Of Iran [http://www.KAPDA.ir]
Disclaimer : VUPEN Security does not endorse the content of this
message submitted by others to public mailinglists. Messages submitted to public
mailinglists do not necessarily reflect the opinions or policies of VUPEN Security.
VUPEN Security makes no warranties, express or implied, as to the content of the message
in this page or the accuracy and reliability of any messages and other materials
submitted to public mailinglists. Any questions or comments regarding this page
should be sent to
team@vupen.com
|
|
|
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|