[UNIX] XOOPS RC3 Script Injection Vulnerability

From: support@securiteam.com
Date: 09/24/02


From: support@securiteam.com
To: list@securiteam.com
Date: Tue, 24 Sep 2002 19:57:44 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  XOOPS RC3 Script Injection Vulnerability
------------------------------------------------------------------------

SUMMARY

 <http://www.xoops.org/> XOOPS is a dynamic OO (Object Oriented) based
open source portal script written in PHP. XOOPS is the ideal tool for
developing small to large dynamic community websites, intra company
portals, corporate portals, weblogs and much more. A vulnerability in the
product allows remote attackers to cause the product to insert malicious
HTML or JavaScript into existing pages.

DETAILS

Vulnerable systems:
 * XOOPS RC3.0.4 and possibly previous versions

The problem appears when a user posts a news item, and inserts the
following text:
<IMG SRC="javascript:[javascript]">

Vendor status:
Das tried to inform someone from Xoops.org but the website was not
available, therefore Das informed the French team. They were not aware of
the issue therefore, they transmitted it to the Dev Team. The Dev Team had
already located the vulnerability that is not specific to XOOPS but with a
large portion of their scripts. In future version, a new filter will be
inserted in the text sanitizer to avoid this risk.

Workaround:
Disabling the ability to post HTML based messages.

ADDITIONAL INFORMATION

This vulnerability's original paper can be found here:
 <http://www.echu.org/modules/news/article.php?storyid=95>
http://www.echu.org/modules/news/article.php?storyid=95

The information has been provided by <mailto:das@hush.com> das.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [Full-Disclosure] [SCSA-011] Path Disclosure Vulnerability in XOOPS
    ... XOOPS is "a dynamic OO based open source portal script ... dynamic community websites,intra company portals, corporate portals, ... A vulnerability have been found in XOOPS which allow attackers to determine ... Exploits Path Disclosure: ...
    (Full-Disclosure)
  • [UNIX] Path Disclosure Vulnerability in XOOPS
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... housewarming rates on automated network vulnerability ... XOOPS is the ideal tool for ... portals, corporate portals, weblogs and much more". ...
    (Securiteam)
  • Re: Xoops RC3 script injection vulnerability
    ... >PROGRAM: Xoops ... >IMMUNE VERSIONS: no immune current versions ... problem so they transmitted it to the Dev Team. ... located the vulnerability which is not specific to Xoops but with much of ...
    (Bugtraq)
  • [UNIX] XOOPS myheader.php Cross Site Scripting Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... making XOOPS an ideal tool for developing small to ... portals, weblogs and much more". ... cross-site scripting vulnerability. ...
    (Securiteam)
  • [UNIX] XOOPS RC3 WebChat Module SQL Injection
    ... XOOPS is a dynamic OO based open source portal script ... dynamic community websites, intra company portals, corporate portals, ... The information in this bulletin is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)