XSS & Path Disclosure in Chipmunk’s products

XSS & Path Disclosure in Chipmunk’s products

漏洞ID 1053304 漏洞类型
发布时间 2005-10-21 更新时间 2005-10-21
图片[1]-XSS & Path Disclosure in  Chipmunk’s  products-安全小百科CVE编号 CVE-2005-3514


CVE-2005-3515


CVE-2005-3516


CVE-2005-3517

图片[2]-XSS & Path Disclosure in  Chipmunk’s  products-安全小百科CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2005100046
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Products: Chipmunk >> ( Forum , Topsites , Directory )
, [ Guestbook ]
Versions: Tested: Last released of products
Vendor: http://chipmunk-scripts.com
Bug: ( XSS ) , [ Path Disclosure ]
Exploitation: Remote
---------------------------
Introduction:
Chipmunk Forum is a small yet flexible and fully
featured forum system.
Chipmunk Topsites is a flexible topsite system
utilizing PHP4/mysql.
Chipmunk Directory is a powerful link indexing script.
Chipmunk Guestbook is an easy to use yet powerful
guestbook with a customizable layout
---------------------------
vulnerability:XSS ( Forum , Topsites , Directory )
XSS Vulnerability in multiple PHP pages that may allow
a remote user to launch cross-site scripting attacks.
A remote user can create a specially crafted URL that,
when loaded by a target user, will cause arbitrary
scripting code to be executed by the target user's
browser. The code will originate from the site running
the software and will run in the security context of
that site. As a result, the code will be able to
access the target user's cookies (including
authentication cookies), if any, associated with the
site, access data recently submitted by the target
user via web form to the site, or take actions on the
site acting as the target user.
vulnerability:Path Disclosure [ Guestbook ]
A remote user can supply a specially crafted URL to
cause the system to display an error message that
discloses the installation path and other data.
----------------------------
Demonstration XSS URL :
http://example.com/board/newtopic.php?forumID='%3C/a>%3CIFRAME%20SRC=jav
ascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
http://example.com/board/quote.php?forumID='%3C/a>%3CIFRAME%20SRC=javasc
ript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
& [ board/index.php , board/reply.php ]
http://example.com/topsites/recommend.php?ID='%3C/a>%3CIFRAME%20SRC=java
script:alert(%2527xss%2527)%3E%3C/IFRAME%3E

http://example.com/directory/recommend.php?entryID='%3C/a>%3CIFRAME%20SR
C=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
Demonstration Path Disclosure  URL :
http://example.com/guestbook/index.php?start='

-----------------------------
Solution:
There is no vendor-supplied patch for this issue at
this time.
-------------------------------
Credits:
Discovered & released by trueend5
Security Science Researchers Institute Of Iran
[KAPDA.ir]
Original Advisory:
http://irannetjob.com/content/view/148/28/

__________________________________ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com

相关推荐: Fusion News 3.3 – Unauthorized Account Addition

Fusion News 3.3 – Unauthorized Account Addition 漏洞ID 1054102 漏洞类型 发布时间 2003-08-18 更新时间 2003-08-18 CVE编号 N/A CNNVD-ID N/A 漏洞平台 PHP …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享