Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Article suggestion: "wannabe security group members" doing harm to software developers

  [eVuln] MWGuest XSS Vulnerability

  [SA19717] W2B Online Banking "SID" Cross-Site Scripting Vulnerability

  [SA19684] I-Rater Platinum "include_path"
Parameter File Inclusion Vulnerability

From:r0t <krustevs_(at)_googlemail.com>
Date:20.04.2006
Subject:AWStats 6.5.x multiple vuln.

AWStats 6.5.x multiple vuln.

###############################################
Vuln. discovered by : r0t
Date: 20 april 2006
vendorlink:http://awstats.sourceforge.net/
affected versions: 6.5 (build 1.857) and prior
orginal advisory:
http://pridels.blogspot.com/2006/04/awstats-65x-multiple-vuln.html
###############################################


Vuln. Description:

1. Cross-Site Scripting

AWStats contains a flaw that allows a remote cross site scripting attack.
This flaw exists because input passed to
"refererpagesfilter","refererpagesfilterex",
"urlfilterex","urlfilter","hostfilter",
"hostfilterex"
paremeter in "awstats.pl"  isn't properly sanitised before being returned to
the user.
This could allow a user to create a specially crafted URL that would execute
arbitrary code in a user's browser within the trust relationship between the
browser and the server, leading to a loss of integrity.


examples:

/awstats.pl?refererpagesfilter=[XSS]&refererpages
filterex=&output=refererpages&config=unsecured-s
ystems.com&year=2006&month=all

/awstats.pl?refererpagesfilter=&refererpagesfilt
erex=[XSS]&output=refererpages&config=unsecured
-systems.com&year=2006&month=all

/awstats.pl?urlfilter=&urlfilterex=[XSS]&output=
urlentry&config=unsecured-systems.com&year=200
6&month=all

/awstats.pl?urlfilter=[XSS]&urlfilterex=&output=
urlentry&config=unsecured-systems.com&year=200
6&month=all

/awstats.pl?hostfilter=[XSS]&hostfilterex=&output=
allhosts&config=unsecured-systems.com&year=2006&
month=all

/awstats.pl?hostfilter=&hostfilterex=[XSS]&output
=allhosts&config=unsecured-systems.com&year=200
6&month=all



2.Full Path Disclosure.

examples:

/awstats.pl?month=&year=[CODE]
/awstats.pl?pluginmode=[CODE]
/awstats.pl?month=[CODE]


###############################################
Solution:
Edit the source code to ensure that input is properly sanitised.
###############################################
its just today's update..:)
###############################################
More information @ unsecured-systems.com/forum/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru