BugTraq
[Suspected Spam]Vulnerability in Tagcloud for DataLife Engine Feb 07 2010 02:53PM
MustLive (mustlive websecurity com ua)
Hello Bugtraq!

I want to warn you about Cross-Site Scripting vulnerability in Tagcloud
plugin for DataLife Engine (DLE). Which I found at 07.01.2010.

It is similar to XSS vulnerability in 3D Cloud for Joomla
(http://websecurity.com.ua/3883/). About millions of flash files
tagcloud.swf which are vulnerable to XSS attacks I mentioned in my article
XSS vulnerabilities in 34 millions flash files
(http://www.webappsec.org/lists/websecurity/archive/2010-01/msg00035.htm
l).

XSS:

http://site/engine/classes/tagcloud/tagcloud.swf?mode=tags&tagcloud=%3Ct
ags%3E%3Ca+href='javascript:alert(document.cookie)'+style='font-size:+40
pt'%3EClick%20me%3C/a%3E%3C/tags%3E

Code will execute after click. It's strictly social XSS.

Also it's possible to conduct HTML Injection attack, including in those
flash files which have protection (in flash files or via WAF) against
javascript and vbscript URI in parameter tagcloud.

HTML Injection:

http://site/engine/classes/tagcloud/tagcloud.swf?mode=tags&tagcloud=%3Ct
ags%3E%3Ca+href='http://websecurity.com.ua'+style='font-size:+40pt'%3ECl
ick%20me%3C/a%3E%3C/tags%3E

Vulnerable are all versions of Tagcloud plugin.

I mentioned about this vulnerability at my site
(http://websecurity.com.ua/3927/).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus