Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  # MHG Security Team --- Gallery Upload Vulnerabilities

  PHP Live Helper ASP(chat.
php) XSS

  PHPBB 2.0.20 persistent issues with avatars

  [Kurdish Security # 7] Foing Remote File Include Vulnerability [PHPBB]

From:r0t <krustevs_(at)_googlemail.com>
Date:13.05.2006
Subject:FlexChat XSS

FlexChat XSS

###############################################
Vuln. discovered by : r0t (Pridels Sec Crew)
Date: 13 may 2006
vendorlink:http://www.flexchat.net/
affected versions:v.2.0 and prior
orginal advisory:http://pridels.blogspot.com/2006/05/flexchat-xss.html
###############################################


Vuln. Description:

FlexChat contains a flaw that allows a remote cross site scripting
attack. This flaw exists because input passed to "username","CFTOKEN"
parameter in "index.cfm" and input passed to "CFTOKEN","CFID"
parameter in "chat.cfm" isn't properly sanitised before being returned
to the user.
This could allow a user to create a specially crafted URL that would
execute arbitrary code in a user's browser within the trust
relationship between the browser and the server, leading to a loss of
integrity.


###############################################
Solution:
Edit the source code to ensure that input is properly sanitised.
###############################################
More information @ unsecured-systems.com/forum/

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod
 



Rating@Mail.ru