New User, Welcome!     Login

Next Page >>

cross/site scripting attack

OpenCms (7.5.0) - Vulnerability: Cross-Site Scripting, Phishing Through Frames, Application Error

Version: 7.5.0

Hardware: Tomcat/Oracle

Vulnerability: Cross-Site Scripting, Phishing Through Frames,
Application Error


Overview:


Survey: "MIME/Content-Type-Sniffing" Issues in Image Uploads in Forum Scripts

[5] http://secunia.com/advisories/34220/

APPENDIX: Advisories
====================================================

Advisory: “Cross-Site Scripting” in Avatar uploads in fluxBB

Application: fluxBB
Vulnerable Versions: 1.3-legacy and older 1.3 versions.
Reported By: Jacques Copeau


[CVE-2010-0432] Apache OFBiz Multiple XSS Vulnerabilities

Release mode: Coordinated release


2. *Vulnerability Information*

Class: Multiple Cross Site Scripting (XSS)
Remotely Exploitable: Yes
Locally Exploitable: Yes
CVE Name: CVE-2010-0432



[MORNINGSTAR-2009-02] Multiple security issues in Cute News and UTF-8 Cute News

Release Type: Co-ordinated, responsible disclosure


2. Vulnerability Information
------------------------------------------------------------------------------------------------------------------------
Class: Cross Site Request Forgery, Cross Site Scripting, File Path 
Disclosure, Local File Inclusion, Authentication Bypass and PHP Command 
Injection
Remotely Exploitable: Yes
Locally Exploitable: No


CORE-2009-0108: Multiple vulnerabilities in Sun Calendar Express Web Server

Release mode: Coordinated release


2. *Vulnerability Information*

Class: Denial of service (DoS), Cross site scripting (XSS)
Remotely Exploitable: Yes
Locally Exploitable: No
Bugtraq ID: 34150, 34152, 34153
CVE Name: N/A


CORE-2009-0109 - Multiple XSS in Sun Communications Express

Release mode: Coordinated release


2. *Vulnerability Information*

Class: Cross site scripting (XSS)
Remotely Exploitable: Yes
Locally Exploitable: No
Bugtraq ID: 34154, 34155
CVE Name: CVE-2009-1729


Phorum < 5.2.10 Cross-Site Scripting/Request Forgery

#=cicatriz <c1c4tr1z@voodoo-labs.org>=#=~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~(advisories)=#
                                     /)           /)     /)                   
                        _ _  _______(/ ________  // _   (/_ _       _____  _  
                        (/__(_)(_)(_(_(_)(_)    (/_(_(_/_) /_)_ o  (_)/ (_(_/_
                                                                         .-/  
#=Phorum < 5.2.10 Cross-Site Scripting/Request Forgery=#=~~~~~~~~~~~~~~~(_/~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=#
#=~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=#
#=Advisory & Vulnerability Information=#=~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=#

        Title: Phorum < 5.2.10 Cross-Site Scripting/Request Forgery
        Advisory ID: VUDO-2009-1504

WP Comment Remix 1.4.3 Multiple Vulnerabilities

Version: 1.4.3
From: Remote
Severity: Extremely Critical
Impact:
    Manipulation of data
    Cross-Site Scripting
Type of Advisory: Full Disclosure

_________________
Software Description |
===============

net2ftp <= 0.97 Cross-Site Scripting/Request Forgery

#=cicatriz <c1c4tr1z@voodoo-labs.org>=#=~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~(advisories)=#
                                     /)           /)     /)                   
                        _ _  _______(/ ________  // _   (/_ _       _____  _  
                        (/__(_)(_)(_(_(_)(_)    (/_(_(_/_) /_)_ o  (_)/ (_(_/_
                                                                         .-/  
#=net2ftp <= 0.97 Cross-Site Scripting/Request Forgery=#=~~~~~~~~~~~~~~~(_/~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=#
#=~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=#
#=Advisory & Vulnerability Information=#=~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~=#

        Title: net2ftp <= 0.97 Cross-Site Scripting/Request Forgery
        Advisory ID: VUDO-2009-0804

YEKTA WEB Academic Web Tools CMS Multiple XSS

Vulnerabilities:
------------------

        1- Cross Site Scripting (XSS) in "/page.php" in "sid","logincase" and "redirect" parameters.
        http://yoursite/page.php?sid=[XSS]
        http://yoursite/page.php?logincase=[XSS]
        http://yoursite/page.php?redirect=[XSS]
        
        2- Cross Site Scripting (XSS) in "/page_arch.php" in "sid","logincase" and "redirect" parameters.

QuickerSite Multiple Vulnerabilities

                2.3.1. Exploit:
                                Check the exploit section.
        2.4. Failure to Restrict URL Access [in "mailPage.asp"]. Everyone can mailbomb others.
                2.4.1. Exploit:
                                Check the exploit section.
        2.5. Cross Site Scripting (XSS) [in "showThumb.aspx"]. Reflected XSS attack by circumventing the ASP.Net XSS denier (Path disclosure on the open error mode).
                2.5.1. Exploit:
                                Check the exploit section.
        2.6. Cross Site Scripting (XSS), Failure to Restrict URL Access [in "process_send.asp"]. Redirect Reflected XSS Attack In "SB_redirect" parameter. Reflected XSS, Content Spoofing In "SB_feedback" parameter. Everyone can mailbomb others.
                2.6.1. Exploit:
                                Check the exploit section.

TYPO3 Security Bulletin TYPO3-20080611-1: Multiple vulnerabilities in TYPO3 Core

Dear users of TYPO3,

It has been discovered that the default value of the TYPO3 configuration variable fileDenyPattern allows arbitrary code execution on Apache web servers. Besides that, the library fe_adminlib.inc allows Cross Site Scripting (XSS).

=== Component Type ===
TYPO3 Core

=== Affected Versions ===
TYPO3 versions 3.x, 4.0 to 4.0.7, 4.1 to 4.1.6, 4.2


Academic Web Tools CMS <= 1.4.2.8 Multiple Vulnerabilities

                2.1.1. Exploit:
                                                Check the exploit/POC section.
        2.2. Injection Flaws. SQL Injection in "/rating.php" in "book_id" parameter.
                2.2.1. Exploit:
                                                Check the exploit/POC section.
        2.3. Cross Site Scripting (XSS). Reflected XSS attack in "/login.php" in URL parameters.
                2.3.1. Exploit:
                                                Check the exploit/POC section.
        2.4. Cross Site Scripting (XSS). Reflected XSS attack in "/hta/htmlarea.js.php" in "glb_sid" parameters.
                2.3.1. Exploit:
                                                Check the exploit/POC section.                  

Academic Web Tools CMS <= 1.4.2.8 Multiple Vulnerabilities

                2.1.1. Exploit:
                                                Check the exploit/POC section.
        2.2. Injection Flaws. SQL Injection in "/rating.php" in "book_id" parameter.
                2.2.1. Exploit:
                                                Check the exploit/POC section.
        2.3. Cross Site Scripting (XSS). Reflected XSS attack in "/login.php" in URL parameters.
                2.3.1. Exploit:
                                                Check the exploit/POC section.
        2.4. Cross Site Scripting (XSS). Reflected XSS attack in "/hta/htmlarea.js.php" in "glb_sid" parameters.
                2.3.1. Exploit:
                                                Check the exploit/POC section.                  

Academic Web Tools CMS <= 1.4.2.8 Multiple Vulnerabilities

                2.1.1. Exploit:
                                                Check the exploit/POC section.
        2.2. Injection Flaws. SQL Injection in "/rating.php" in "book_id" parameter.
                2.2.1. Exploit:
                                                Check the exploit/POC section.
        2.3. Cross Site Scripting (XSS). Reflected XSS attack in "/login.php" in URL parameters.
                2.3.1. Exploit:
                                                Check the exploit/POC section.
        2.4. Cross Site Scripting (XSS). Reflected XSS attack in "/hta/htmlarea.js.php" in "glb_sid" parameters.
                2.3.1. Exploit:
                                                Check the exploit/POC section.                  

Palo Alto Network Vulnerability - Cross-Site Scripting (XSS)

Class:          Cross-Site Scripting (XSS) Vulnerability
CVE:    CVE-2010-0475
Remote: Yes 
Local:  Yes 
Published: May 11, 2010 08:30AM
Timeline:Submission to MITRE: 1/18/2010
Vendor Contact: 2/18/2010
Vendor Response:  2/18/2010
Patch Available:  5/2010  Patched in maintenance releases (3.1.1 & 3.0.9)
Credit: Jeromie Jackson CISSP, CISM

SEC Consult SA-20090415-0 :: Multiple Vulnerabilities in Novell Teaming

SEC Consult Security Advisory < 20090415-0 >
==========================================================================
              title: Novell Teaming Multiple Vulnerabilities
                     * Username Enumeration
                     * Multiple Cross Site Scripting
                     * Includes vulnerable Liferay portal
            program: Novell Teaming
 vulnerable version: 1.0.3
           homepage: http://www.novell.com/products/teaming/
              found: February 2009

[AK-ADV2008-001] Openfire Jabber-Server: Multiple Vulnerabilities (Authentication Bypass, SQL injection, ...)

It is possible to pass SQL statements to the backend database through
a SQL injection vulnerability. Depending on the particular
runtime environment and database permissions it is even possible to
write files to disk and execute code on operating system level.

3) Multiple Cross-Site Scripting
Permits arbitrary insertion of HTML- and JavaScript code in login.jsp.
An attacker could also manipulate a parameter to specify
a destination to which a user will be forwarded to after successful
authentication.


Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities

Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and
Information Disclosure Vulnerabilities

Advisory-ID: 200801161
Discovery Date: 1.16.2008
Release Date: 1.23.2008
Affected Applications: HFS 2.0 to and including 2.3(Beta Build
#174)
Non-Affected Applications: HFS 1.6a and earlier versions
Class: Cross-Site Scripting (XSS), Information Disclosure

[MORNINGSTAR-2009-01] Multiple security issues in Open Auto Classifieds version <= 1.5.9

Release Type: Co-ordinated, responsible disclosure


2. Vulnerability Information
----------------------------------------------------------------------------------------------
Class: SQL Injection, Insecure File Upload, Cross Site Scripting, 
Filepath Disclosure
Remotely Exploitable: Yes
Locally Exploitable: No



Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome

(http://www.securityfocus.com/archive/1/505251/30/0/threaded). There I made
enough arguments why it's dangerous vulnerability and why Mozilla and
Michal are not right and so it's better to fix it. Read my message at
Bugtraq, maybe it'll change your mind on this issue ;-).

> The best way to defend against any Cross Site Scripting attacks is to
> sanitize all inputs and outputs properly on your website

XSS vulnerabilities must be fixed and when they are made at web sites, then
they must be fixed at web sites. But in this case browsers developers made
XSS holes (JavaScript execution) in redirectors, so they just from

[InterN0T] Pivot 1.40.4-7 - Multiple Vulnerabilities

url, menu, sort, check[], edituser, edit, blog, cat.

Path Disclosure:
http://[HOST]/pivot/pivot/tb.php?tb_id=1&url='

Cross Site Scripting: (can only be triggered when One is not logged in).
http://[HOST]/pivot/pivot/index.php?menu="><script>alert(0)</script><br

Cross Site Scripting: (triggers on logged in administrators only) [low
or no impact due to session-key in url]
http://[HOST]/pivot/pivot/index.php?session=VALIDSESSION&menu=entries&sort="><script>alert(0)</script>

[RT-SA-2009-002] IceWarp WebMail Server: User-assisted Cross Site Scripting in RSS Feed Reader

Advisory: IceWarp WebMail Server: User-assisted Cross Site Scripting in
          RSS Feed Reader

During a penetration test, RedTeam Pentesting discovered that the
IceWarp WebMail Server is prone to user-assisted Cross Site Scripting
attacks in its RSS feed reader. If attackers control or compromise an
RSS feed users are subscribed to, they can run arbitrary JavaScript code
in the users' browsers by embedding it within the feed.



[RT-SA-2009-001] IceWarp WebMail Server: Cross Site Scripting in Email View

Advisory: IceWarp WebMail Server: Cross Site Scripting in Email View

During a penetration test, RedTeam Pentesting discovered that the IceWarp
WebMail Server is prone to Cross Site Scripting attacks in its email view.
This enables attackers to send emails with embedded JavaScript code,
for example, to steal users' session IDs.


Details
=======

FormMail 1.92 Multiple Vulnerabilities

III. ANALYSIS

Summary:

 A) Prelude to the vulnerabities
 B) Cross Site Scripting
 C) HTTP Response Header Injection
 D) HTTP Response Splitting

A) Prelude to the vulnerabities


Cross-Site Scripting vulnerabilities in Invision Power Board

Hello Bugtraq!

I want to warn you about new vulnerabilities in Invision Power Board.

These are Cross-Site Scripting vulnerabilities. Attack is going via 
attachment (at click on the attachment in the post at forum or on the link 
to this attachment). These are persistent XSS vulnerabilities.

I know for a long time about possibility of attacks via swf-files. So many 
years ago I turned off support of swf-files in attachments (and in avatars 

Trustwave's SpiderLabs Security Advisory TWSL2010-001

functionality.

The ASP.Net view state is typically stored in a hidden field
named "__VIEWSTATE". When a page's view state is not
cryptographically signed, many standard .Net controls are
vulnerable to Cross-Site Scripting (XSS) through the view
state.

It is well documented that using an unsigned view state is
"bad", but most previous advisories focus on vaguely
described threats or vulnerabilities introduced by custom

(resend) RE: [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2010-001

functionality.

The ASP.Net view state is typically stored in a hidden field
named "__VIEWSTATE". When a page's view state is not
cryptographically signed, many standard .Net controls are
vulnerable to Cross-Site Scripting (XSS) through the view
state.

It is well documented that using an unsigned view state is
"bad", but most previous advisories focus on vaguely
described threats or vulnerabilities introduced by custom

RE: [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2010-001

functionality.

The ASP.Net view state is typically stored in a hidden field
named "__VIEWSTATE". When a page's view state is not
cryptographically signed, many standard .Net controls are
vulnerable to Cross-Site Scripting (XSS) through the view
state.

It is well documented that using an unsigned view state is
"bad", but most previous advisories focus on vaguely
described threats or vulnerabilities introduced by custom

RE: [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2010-001

functionality.

The ASP.Net view state is typically stored in a hidden field
named "__VIEWSTATE". When a page's view state is not
cryptographically signed, many standard .Net controls are
vulnerable to Cross-Site Scripting (XSS) through the view
state.

It is well documented that using an unsigned view state is
"bad", but most previous advisories focus on vaguely
described threats or vulnerabilities introduced by custom

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!