[NT] ASP-Dev Multiple Cross Site Scripting Vulnerabilities

From: SecuriTeam (support_at_securiteam.com)
Date: 04/03/05

  • Next message: SecuriTeam: "[UNIX] Linux Kernel Ext2 Implementation Information Leak"
    To: list@securiteam.com
    Date: 3 Apr 2005 13:55:02 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      ASP-Dev Multiple Cross Site Scripting Vulnerabilities
    ------------------------------------------------------------------------

    SUMMARY

     <http://asp-dev.com/> ASP-Dev is "a web based forum written in ASP
    language".

    The bbcode parsed by the forum code allows attackers to input JavaScript
    code into the forum. By exploiting this vulnerability attackers can steal
    information such as cookies from users.

    DETAILS

    Vulnerable Systems:
     * Asp-Dev FORUM version Rc3

    When posting a message to the forum, an attacker can add Javascript code
    between bbcode instructions.

    Proof of Concept:
    [IMG]javasc+ript:alert(document.cookie)[/IMG]

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:zinho@hackerscenter.com>
    Zinho.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] Linux Kernel Ext2 Implementation Information Leak"

    Relevant Pages

    • [UNIX] YaBB Forum member.vars CRLF Injection Privilege Escalation Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... YaBB Forum member.vars CRLF Injection Privilege Escalation Vulnerability ... input validation error within version 2.1 of YaBB Forum allows attackers ... their privileges to that of the forum Administrator. ...
      (Securiteam)
    • [UNIX] myPHP Forum Unauthorized Access
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... MySQL and PHP based forum. ... Lack of validation checks allows myPHP forum user to create new categories ...
      (Securiteam)
    • [NT] AOL Nullsoft Winamp Ultravox Lyrics3 v2.00 tags Heap Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... AOL Nullsoft Winamp Ultravox Lyrics3 v2.00 tags Heap Overflow ... Exploitation allows remote attackers to execute code in the context of the ...
      (Securiteam)
    • [UNIX] GPhotos Multiple Vulnerabilities
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... GPhotos Multiple Vulnerabilities ... as allow attackers to insert arbitrary HTML and/or JavaScript. ...
      (Securiteam)
    • [UNIX] My Little Forum XSS Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... My Little Forum is "a ... scripting vulnerability in the product allows remote attackers to insert ...
      (Securiteam)