[VulnWatch] [SCSA-008] Cross Site Scripting & Script Injection Vulnerability in PY-Livredor

From: Gregory Le Bras | Security Corporation (gregory.lebras@security-corp.org)
Date: 03/02/03

  • Next message: Frog Man: "[VulnWatch] WebChat (PHP)"
    From: "Gregory Le Bras | Security Corporation" <gregory.lebras@security-corp.org>
    To: <vulnwatch@vulnwatch.org>
    Date: Sun, 2 Mar 2003 22:32:58 +0100
    
    

    ________________________________________________________________________

    Security Corporation Security Advisory [SCSA-008]
    ________________________________________________________________________

    PROGRAM: PY-Livredor
    HOMEPAGE: http://www.py-scripts.com
                           http://www.scripts-php.com
    VULNERABLE VERSIONS: v1.0
    ________________________________________________________________________

    DESCRIPTION
    ________________________________________________________________________

    PY-Livredor is an easy guestbook script using Php4 and MySql with
    an administration which allow messages deletion.

    DETAILS
    ________________________________________________________________________

    A Cross-Site Scripting vulnerability have been found in PY-Livredor
    which allow attackers to inject script codes into the guestbook and use
    them on clients browser as if they were provided by the website.

    This Cross-Site Scripting vulnerability are found in the page for
    posting messages (index.php)

    An attacker can input specially crafted links and/or other
    malicious scripts.

    EXPLOIT
    ________________________________________________________________________

    A vulnerability was discovered in the page for posting messages,
    at this adress :

    http://[target]/livredor/index.php

    The vulnerability is at the level of the interpretation of the "titre",
    "Votre pseudo", "Votre e-mail", "Votre message" fields.

    Indeed, the insertion of a hostile code script in this field makes it
    possible to a malicious user to carry out this script on the navigator
    of the visitors.

    The hostile code could be :

    [script]alert("Cookie="+document.cookie)[/script]

    (open a window with the cookie of the visitor.)

    (replace [] by <>)

    SOLUTIONS
    ________________________________________________________________________

    No solution for the moment.

    VENDOR STATUS
    ________________________________________________________________________

    The vendor has reportedly been notified.

    LINKS
    ________________________________________________________________________

    http://www.security-corp.org/index.php?ink=4-15-1

    Version Française :

    http://www.security-corp.org/advisories/SCSA-008-FR.txt

    ------------------------------------------------------------
    Grégory Le Bras aka GaLiaRePt | http://www.Security-Corp.org
    ------------------------------------------------------------



    Relevant Pages

    • SecurityFocus Microsoft Newsletter #83
      ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft IIS CodeBrws.ASP Source Code Disclosure Vulnerability ... Microsoft Internet Explorer History List Script Injection ... Microsoft Windows 2000 Lanman Denial of Service Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #84
      ... The most critical piece of vulnerability assessment is remediation. ... MICROSOFT VULNERABILITY SUMMARY ... IcrediBB Script Injection Vulnerability ... WorkforceROI XPede Unprotected Administrative Facilities... ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #91
      ... SecurityFocus Microsoft Newsletter #91 ... Multiple Bugzilla Security Vulnerabilities ... Geeklog pid CGI Variable SQL Injection Vulnerability ... Geeklog Calendar Event Form Script Injection Vulnerability ...
      (Focus-Microsoft)
    • SecurityFocus Microsoft Newsletter #109
      ... MICROSOFT VULNERABILITY SUMMARY ... PHPRank Banner Script Code Injection Vulnerability ... PHPNuke Multiple Script Code Filtering Vulnerabilities ...
      (Focus-Microsoft)
    • HP Web JetAdmin vulnerabilities.
      ... this vulnerability is not a critical risk. ... Luckily these directories do not have execute permissions but, this script, ... create files in the Administrators startup folder. ... it may be possible to directly inject the hts scripting ...
      (Bugtraq)