PHPSysInfo Index.php Cross Site Scripting



[HSC] PHPSysInfo Index.php Cross Site Scripting


PhpSysInfo is a PHP script that displays information about the host being accessed.
An attacker may leverage this issue to have arbitrary script code execute
in the browser of an unsuspecting user in the context of the affected site.
This may help the attacker steal cookie-based authentication credentials and
launch other attacks. A successful exploit could allow an attacker to compromise
the application, access or modify data, or exploit vulnerabilities in the
underlying database implementation.


Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz

Class: Input Validation Error

Remote: Yes
Local: N/A

Product: PHPSysInfo
Version: phpSysInfo-2.5.4 *Other version are be vulrnable.
Vendor: http://phpsysinfo.sourceforge.net/


Exploit is not needed, Attackers can exploit these issues via a web client.

Exploit: http://www.Site.com/phpsysinfo-path/index.php/XSS


Only becoming a hacker you can stop a hacker. Were can you learn with out having
to pay thousands!- http://kit.hackerscenter.com - The most comprehensive security
pack you will ever find on the net!



Relevant Pages

  • Re: cross site scripint and post form
    ... cross site scripint and post form ... Its easier with the GET method because, as you have noticed, the attacker ... script tags out of the input with your client code -The attacker can still ...
    (Security-Basics)
  • Re: Strange Attack On A Webserver I Work On
    ... My guess is that this guy definitely was a script kiddie. ... If you Google for the e-mail addresses that appear in the flooder ... >> The attacker replaced all ...
    (Focus-Linux)
  • [UNIX] phpSysInfo Multiple Vulnerabilities (HTTP_ACCEPT_LANGUAGE, sensor_program, VERSION, charset)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities have been discovered in phpSysInfo allowing ... the attacker to additionally inject the $lng parameter. ... $sensor_program can *still* be used to inject active ...
    (Securiteam)
  • e107 v0.617 several new and old vulnerabilities
    ... PHP and SQL based portal and content ... An attacker may use this information ... plugins are usually saved as a sub-directory of the default path ... Also the use of cross site scripting attacks in the tested ways is not ...
    (Bugtraq)
  • NextPlace.com E-Commerce ASP Engine
    ... Any attacker can fake messages, and betray the trust of all the people who ... XSS appears and the server allows an attacker to inject & execute scripts. ... and script code will be executed by their web client. ...
    (Bugtraq)