exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

serendipityfreetag-xss.txt

serendipityfreetag-xss.txt
Posted Feb 8, 2008
Authored by Alexander Brachmann

The Serendipity Freetag-plugin versions 2.95 and below suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | fd61cae107420ceef7d7957b173652b1f0d27271301925481e0c302623a2d68f

serendipityfreetag-xss.txt

Change Mirror Download
* Advisory: Serendipity Freetag-plugin XSS vulnerability

* Application: Serendipity Freetag-plugin =< 2.95
* Category: Web application
* Class: Cross Site Scripting (XSS)
* Release date: 08. February 2008
* Last updated: 08. February 2008
* Remote: Yes
* Local: No
* CVE: Not yet assigned
* Credits: Alexander Brachmann (research@bitsploit.de)
* Author of advisory: Alexander Brachmann (research@bitsploit.de)
* Severity: An XSS flaw was discovered in the optional Freetag-plugin
for Serendipity (popular weblog application). E.g., this could lead to a
hijacked Serendipity account.
* Risk: High
* Vendor/Project/Programmer(s): Garvin Hicking, Jonathan Arkell, Grischa
Brockhaus
* Solution status: The programmers have fixed this flaw in Freetag
version 2.96.
* References:
[1]
https://blog.s9y.org/archives/190-Freetag-plugin-updated-to-prevent-XSS.html
[2] https://www.bitsploit.de/uploads/Code/200802080000/
[3] https://www.bitsploit.de/uploads/Bilder/200802101012/s9y-xss.jpg


* Overview:
Quote from www.s9y.org:
"Serendipity is a PHP-powered weblog application which gives the user an
easy way to maintain an online diary, weblog or even a complete
homepage. While the default package is designed for the casual blogger,
Serendipity offers a flexible, expandable and easy-to-use framework with
the power for professional applications.
Casual users appreciate the way Serendipity's sophisticated plugin
architecture allows you to easily modify both the appearance of your
blog and its features.
You can install more than 120 plugins with just one click, instantly
enhancing your blog's functionality."

While testing Serendipity an XSS flaw was discovered in the optional
plugin for tagging entries called "Freetag". For example, this could
lead to a hijacked Serendipity account.


* Details:
The Freetag-plugin displays the tag name, specified in a URL, back to
the user.
Due to a defective sanitization of the user's input, it is possible to
inject arbitrary code which will be reflected on the website.


* Proof of Concept (PoC):
URL:
https://www.example.com/plugin/tag/%3Cdiv%20style=width:expression(alert(document.cookie));%3E
Hint: PoC does currently work in Microsoft Internet Explorer 6,
Microsoft Internet Explorer 7 and Netscape Navigator 8.1+ (in Internet
Explorer rendering mode) only.


* Solution:
We strongly recommend you to upgrade to Freetag version 2.96 which fixes
this flaw.
URL:
https://spartacus.s9y.org/cvs/additional_plugins/serendipity_event_freetag.zip


* Disclosure timeline:
05. February 2008 - Flaw was discovered and re-checked.
06. February 2008 - Programmers have been notified. (Due to responsible
disclosure.)
06. February 2008 - Fix was committed.
07. February 2008 - Freetag 2.96 released to the public.
08. February 2008 - Public disclosure.


* GPG:
E-Mail: research@bitsploit.de
Public key: https://www.bitsploit.de/gpg/domains/public_key.asc
Key ID: 0x75093340
Key Fingerprint: D542 669B 02F8 7874 F75A A44C AA0B 41FC 7509 3340


* Copyright:
Creative Commons - by - Version 3.0
URL: https://creativecommons.org/licenses/by/3.0/deed.en

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close