BugTraq
ZH2003-15SA (security advisory): IdealBB XSS Vulnerability Aug 08 2003 12:47PM
G00db0y (G00db0y zone-h org)


ZH2003-15SA (security advisory): IdealBB XSS Vulnerability

Published: 7 august 2003

Released: 7 august 2003

Name: IdealBB

Affected Systems: 1.4.9 beta

Issue: Remote attackers can inject XSS script

Author: G00db0y (at) zone-h (dot) org [email concealed]

Vendor: http://www.idealbb.com

Description

***********

Zone-h Security Team has discovered a flaw in

IdealBB 1.4.9 (and older versions?). "The Ideal Bulletin Board

(Ideal BB) is a powerful, scalable, and very user friendly

bulletin board program that utilitzes SQL server on the backend

and ASP and COM on the front end."

Details

*******

error.asp which is supposed to handle error messages,seems unfiltered

agains Cross-Site Scripting. Which is allow any attacked to inject XSS

script.

Example:

http://www.site.com/idealbb/error.asp?e=16&sessionID={xxxxxxxx-xxxx-xxxx
-

xxxx-xxxxxxxxxxxx}&msg=<script>alert('Zone-h')</script>

Solution:

*********

The vendor has been contacted and a patch was produced

Suggestions:

************

Filter the script

G00db0y - www.zone-h.org admin

Original advisory here: http://www.zone-h.org/en/advisories/read/id=2838/

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus