what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

CyberKendra Search Bar Cross Site Scripting

CyberKendra Search Bar Cross Site Scripting
Posted Jun 23, 2013
Authored by Prakhar Prasad, Rafay Baloch

The CyberKendra Search Bar script suffered from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 4a5361a17f69d745e0fb5aa52190ed508bceb7f198b3fd490a70d9e77ed8a4eb

CyberKendra Search Bar Cross Site Scripting

Change Mirror Download
[RHA InfoSec] CyberKendra Search Bar Script DOM Based XSS Vulnerability

Details
=============

Risk: Moderated
Vendor-URL: https://www.cyberkendra.com/

Credits
=============
Discovered by: Rafay Baloch And Prakhar Prasad of RHA InfoSec
Blog: https://rafayhackingarticles.net

Description
============

Cyber Kendra wrote a custom search script that allowed the users to easily
search for
stuff on their website.

Vulnerability Details
======================

The vulnerability is a DOM Based xss vulnerability, as our payload was
being embedded into the
DOM and was being returned to the user without proper escaping which
resulted in a DOM Based XSS.

The showresult Function contained the following code, where the input was
being executed
via innerhtml without being sanitised. The skeleton is our user
controllable parameter.


skeleton="<h4>"+config.resultTitle+" ""+input.value+""</h4>"
resultContainer.innerHTML=skeleton;


Fix
===

We reported the vulnerability to CyberKendra team and also pointed to the
vulnerable code.
However, instead of fixing it, they just removed the whole search script.


--
Warm Regards,
Rafay Baloch

https://rafayhackingarticles.net
https://techlotips.com
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close