[Full-disclosure] HYSA-2005-009 Elite Forum 1.0.0.0 XSS Vulnerability

From: h4cky0u (h4cky0u.org_at_gmail.com)
Date: 11/01/05

  • Next message: ad_at_class101.org: "RE: [Full-disclosure] for IE researchers, found a link crashing IE"
    Date: Tue, 1 Nov 2005 15:16:13 +0530
    To: full-disclosure@lists.grok.org.uk
    
    
    

    ------------------------------------------------------
    HYSA-2005-009 h4cky0u.org <http://h4cky0u.org> Advisory 009
    ------------------------------------------------------
    Date - Tue Nov 1 2005

    TITLE:
    ======

    Elite Forum 1.0.0.0 <http://1.0.0.0> XSS Vulnerability

    SEVERITY:
    =========

    Medium

    SOFTWARE:
    =========

    Elite Forum 1.0.0.0 <http://1.0.0.0>

    INFO:
    =====

    Elite Forum is a fierce competitor entering the world of forum systems.
    Unlike many other choices, Elite Forum does not

    require the hassle of a MySQL database. Elite Forum is one of the best and
    is packed full of features, including the

    following: No MySQL database required, Very easy installation, Support for
    both user registration and guests, Private

    Messaging System, Forum can be locked so registration is required, User,
    forum and topic statistics, Fast and easy to use

    search system, Ability to view who is currently browsing the forum, Sticky
    Topics (Announcements), Full member list,

    Unlimited users, topics and posts, Member Profiles/Stats, Multiple page
    support (both topics and posts user definable),

    Selectable time offset, Ability to auto check for updates/patches, Clean and
    streamlined design, Smiley Support, BB Code and

    auto url support, Topic status icons, Member and Guest user levels, Members
    can edit or delete their posts, Secure accounts,

    Add or remove admins via administrator panel, Admins can edit/delete any
    post or topic.

    Support Website :
    www.all-interviews.com/firestorm/?act=eliteforum<http://www.all-interviews.com/firestorm/?act=eliteforum>(Down
    at the time of Bug Discovery)

    BUG DESCRIPTION:
    ================

    The system is vulnerable to Cross Site Scripting attacks. This issue is due
    to a failure of the application to properly

    sanitize user-supplied input.

    POC:
    ====

    First find a forum running the Elite Forum package. Then click on a topic
    and then Post Reply. In the message box add any of

    the following codes. Here are some examples:

    <img src="javascript:void(window.location=('imagelink'))"> - Replace the
    imagelink with the link to the image you want to

    redirect the users viewing the topic containing this code.

    <img src="javascript:a=100;while(a>=0){alert(a);a--}">

    <img src="javascript:a=1;while(a>0){alert("sup?")">

    VENDOR STATUS:
    ==============

    The support site is down and no vendor contact could be found.

    FIX:
    ====

    No fix available as of date.

    GOOGLEDORK:
    ===========

    "Powered by Elite Forum"

    CREDITS:
    ========

    This vulnerability was discovered and researched by
    Gladiator.KHF(handle/username - gladiator) of h4cky0u Security Forums.

    mail : gleden123 at Yahoo dot Com

    web : http://www.h4cky0u.org

    ORIGINAL ADVISORY:
    ==================

    http://www.h4cky0u.org/advisories/HYSA-2005-009-elite-forum.txt

    --
    http://www.h4cky0u.org
    (In)Security at its best...
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: ad_at_class101.org: "RE: [Full-disclosure] for IE researchers, found a link crashing IE"

    Relevant Pages

    • RE: Apache2 Manhattan Virtual Classroom
      ... this is a community supported distribution and forum. ... Turnaround" I have had several posts regarding this sent to this forum ... service as a Gold support contract from Sun. ... My intent was not to flame to or be angry, ...
      (Debian-User)
    • Re: ENTOURAGE STOPPED SYNCING & DOING SIMPLE FINDS - PLEASE HELP
      ... newsgroup, so I don't know much about it. ... customer support to Mac Office users. ... we see more and more posts without any detail (like: ... not a moderated tech support forum and really there aren't rules. ...
      (microsoft.public.mac.office.entourage)
    • Re: Getting Diagnostic Output From Publish Now
      ... The existing threads in this newsgroup will not be moved to the forum. ... Microsoft Online Community Support ... Get notification to my posts through email? ...
      (microsoft.public.dotnet.languages.vb)
    • Re: Any recommendations for a software protection tool?
      ... Horst Reichert napsal: ... The answers to the posts in the forum are fast and of high quality. ... No need for support is the best support. ...
      (borland.public.delphi.thirdpartytools.general)
    • Re: OS X compile
      ... and their posts are wrong and need correcting. ... Angband, but people keep trying to change the subject to whether I'm this Neo guy or not, for some silly reason, and the ones that think I am keep pestering me because they don't like him. ... This is supposed to be a forum for discussing Angband, not a forum for discussing Neo or for calling people names that you think might be Neo. ...
      (rec.games.roguelike.angband)