[Full-Disclosure] [SCSA-007] Cross Site Scripting Vulnerabilities in WWWBoard

From: Grégory Le Bras | Security Corporation (gregory.lebras@security-corp.org)
Date: 02/23/03

  • Next message: Knud Erik Højgaard: "[Full-Disclosure] sircd proof-of-concept / advisory"
    From: Grégory Le Bras | Security Corporation <gregory.lebras@security-corp.org>
    To: <full-disclosure@lists.netsys.com>
    Date: Sun, 23 Feb 2003 03:28:40 +0100
    

    ________________________________________________________________________

    Security Corporation Security Advisory [SCSA-007]
    ________________________________________________________________________

    PROGRAM: WWWBoard
    HOMEPAGE: http://www.scriptarchive.com
    VULNERABLE VERSIONS: 2.0A2.1 and prior
    ________________________________________________________________________

    DESCRIPTION
    ________________________________________________________________________

    WWWBoard is "A threaded discussion forum that allows users to post
    new messages, followup to existing ones and more. Includes a basic
    admin to maintain the board."

    (direct quote from WWWBoard website)

    DETAILS
    ________________________________________________________________________

    A Cross-Site Scripting vulnerability have been found in WWWBoard
    which allow attackers to inject script codes into the forum and use them
    on clients browser as if they were provided by the site.

    This Cross-Site Scripting vulnerability are found in the page for
    posting messages.

    An attacker can input specially crafted links and/or other
    malicious scripts.

    EXPLOIT
    ________________________________________________________________________

    A vulnerability was discovered in the page for posting messages,
    at this adress :

    http://[target]/wwwboard/wwwboard.html#post

    The vulnerability is at the level of the interpretation of the "Message"
    field.

    Indeed, the insertion of a hostile code script in this field makes it
    possible to a malicious user to carry out this script on the navigator
    of the visitors.

    The hostile code could be :

    [script]alert("Cookie="+document.cookie)[/script]

    (open a window with the cookie of the visitor.)

    (replace [] by <>)

    SOLUTIONS
    ________________________________________________________________________

    No solution for the moment.

    VENDOR STATUS
    ________________________________________________________________________

    The vendor has reportedly been notified.

    LINKS
    ________________________________________________________________________

    http://www.security-corp.org/index.php?ink=4-15-1

    Version Française :

    http://www.security-corp.org/advisories/SCSA-007-FR.txt

    ------------------------------------------------------------
    Grégory Le Bras aka GaLiaRePt | http://www.Security-Corp.org
    ------------------------------------------------------------

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • [SCSA-007] Cross Site Scripting Vulnerabilities in WWWBoard
      ... Security Corporation Security Advisory ... WWWBoard is "A threaded discussion forum that allows users to post ... A Cross-Site Scripting vulnerability have been found in WWWBoard ... the insertion of a hostile code script in this field makes it ...
      (Bugtraq)
    • SecurityFocus Microsoft Newsletter #83
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability ... Microsoft Internet Explorer History List Script Injection ... Microsoft Windows 2000 Lanman Denial of Service Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #84
      ... The most critical piece of vulnerability assessment is remediation. ... MICROSOFT VULNERABILITY SUMMARY ... IcrediBB Script Injection Vulnerability ... WorkforceROI XPede Unprotected Administrative Facilities... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #91
      ... SecurityFocus Microsoft Newsletter #91 ... Multiple Bugzilla Security Vulnerabilities ... Geeklog pid CGI Variable SQL Injection Vulnerability ... Geeklog Calendar Event Form Script Injection Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #109
      ... MICROSOFT VULNERABILITY SUMMARY ... PHPRank Banner Script Code Injection Vulnerability ... PHPNuke Multiple Script Code Filtering Vulnerabilities ...
      (Focus-Microsoft)