Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19108
HistoryFeb 13, 2008 - 12:00 a.m.

[Full-disclosure] Serendipity Freetag-plugin XSS vulnerability

2008-02-1300:00:00
vulners.com
53
  • Advisory: Serendipity Freetag-plugin XSS vulnerability

  • Application: Serendipity Freetag-plugin =< 2.95

  • Category: Web application

  • Class: Cross Site Scripting (XSS)

  • Release date: 08. February 2008

  • Last updated: 08. February 2008

  • Remote: Yes

  • Local: No

  • CVE: Not yet assigned

  • Credits: Alexander Brachmann ([email protected])

  • Author of advisory: Alexander Brachmann ([email protected])

  • Severity: An XSS flaw was discovered in the optional Freetag-plugin
    for Serendipity (popular weblog application). E.g., this could lead to a
    hijacked Serendipity account.

  • Risk: High

  • Vendor/Project/Programmer(s): Garvin Hicking, Jonathan Arkell, Grischa
    Brockhaus

  • Solution status: The programmers have fixed this flaw in Freetag
    version 2.96.

  • References:
    [1]
    http://blog.s9y.org/archives/190-Freetag-plugin-updated-to-prevent-XSS.html
    [2] http://www.bitsploit.de/uploads/Code/200802080000/
    [3] http://www.bitsploit.de/uploads/Bilder/200802101012/s9y-xss.jpg

  • Overview:
    Quote from www.s9y.org:
    "Serendipity is a PHP-powered weblog application which gives the user an
    easy way to maintain an online diary, weblog or even a complete
    homepage. While the default package is designed for the casual blogger,
    Serendipity offers a flexible, expandable and easy-to-use framework with
    the power for professional applications.
    Casual users appreciate the way Serendipity's sophisticated plugin
    architecture allows you to easily modify both the appearance of your
    blog and its features.
    You can install more than 120 plugins with just one click, instantly
    enhancing your blog's functionality."

While testing Serendipity an XSS flaw was discovered in the optional
plugin for tagging entries called "Freetag". For example, this could
lead to a hijacked Serendipity account.

  1. February 2008 - Flaw was discovered and re-checked.
  2. February 2008 - Programmers have been notified. (Due to responsible
    disclosure.)
  3. February 2008 - Fix was committed.
  4. February 2008 - Freetag 2.96 released to the public.
  5. February 2008 - Public disclosure.

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/