Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Barracuda vuln.

  TextFileBB 1.0.16 Multiple XSS

  TopList <= 1.3.8 (PHPBB Hack) Remote File Inclusion Vulnerability

  XSS Attack On DirectAdmin Hosting Managment

From:r0t <krustevs_(at)_googlemail.com>
Date:30.04.2006
Subject:OrbitHYIP XSS

OrbitHYIP XSS

###############################################
Vuln. discovered by : r0t
Date: 30 april 2006
vendor:www.orbitscripts.com/orbithyip_overview.html
affected versions:2.0 and prior
orginal advisory:http://pridels.blogspot.com/2006/04/orbithyip-xss.html
###############################################

Vuln. Description:

OrbitHYIP contains a flaw that allows a remote cross site scripting attack.
This flaw exists because input passed to "referral" parameter in "signup.php"
and input passed to "id" parameter in "members.php" isn't properly sanitised
before being returned to the user.
This could allow a user to create a specially crafted URL that would execute
arbitrary code in a user's browser within the trust relationship between the
browser and the server, leading to a loss of integrity.

examples:

/signup.php?referral=[XSS]
/members.php?login=r0t&p=pwd&func=useinvestplan&id=[XSS]


###############################################
Solution:
Edit the source code to ensure that input is properly sanitised.
###############################################
More information @ unsecured-systems.com/forum/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server