b2evolution XSS Vulnerabilities



_________________________________________
Security Advisory
_________________________________________
_________________________________________

Severity: Medium
Title: b2evolution XSS Vulnerability
Date: 28.11.06
Author: tarkus (tarkus (at) tiifp (dot) org)
Web: https://tiifp.org/tarkus
Vendor: b2evolution (http://b2evolution.net/)
Affected Product(s): b2evolution 1.8.2 - 1.9 beta
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Description:
------------

http://<victim>/<b2epath>/inc/VIEW/errors/_404_not_found.page.php?bas \
eurl=[XSS]&app_name=[XSS]

http://<victim>/<b2epath>/inc/VIEW/errors/_410_stats_gone.page.php?ap \
p_name=[XSS]

http://<victim>/<b2epath>/inc/VIEW/errors/_referer_spam.page.php?ReqU \
RI=[XSS]&app_name=[XSS]



Workaround:
-----------

Put the following line at the beginning of the files.

if( !defined('EVO_MAIN_INIT') ) die( 'Please, do not access this page \
directly.' );



Timeline:
---------

Reported to Vendor: 10.11.06
Vendor response: 10.11.06
Patch in CVS: 10.11.06



Relevant Pages

  • Re: Show me function
    ... Well, the vendor is Microsoft. ... within Office 2K Help files. ... Internet Security Settings ... Local Internet - Medium Low ...
    (microsoft.public.access.modulesdaovba)
  • [[ TH 026 Inc. ]] SA #2 - IcrediBB 1.1, Cross Site Scripting vulnerability.
    ... Impact: Medium ... Vendor has been notified of all issues ... A Cross Site Scripting has been found due to insufficient checking of user ... things in MSIE * with evil javascript. ...
    (Bugtraq)
  • Re: QuickTime Formats/Codecs
    ... QT is rather simple, just get QT pro and export to MPEG 4, which is a vendor and platform independent "standard", on the level of the medium itself, which does not help you very much. ...
    (comp.multimedia)
  • Re: Bernie: You Need to Play Deeper
    ... soft fly that hung up to medium center. ... getting cracker jacks from the vendor in center. ... The ball was definitely catchable and deeper than the one Lofton took ...
    (alt.sports.baseball.ny-yankees)
  • GrayCMS php code injection
    ... ('binary' encoding is not supported, ... Severity: High ... Vendor: http://gcms.graymur.net/ ... ghc, 0xdeadbabe, unl0ck & others ...
    (Bugtraq)